6.4
/ 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:H/SI:H/SA:H
Description
SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow reading and executing files previously added through the backup functionality. Critically, due to CVE-2026-40543 (Missing Authorization), any backup file can be read by any (unauthorized) user.
This issue affects SOPlanning version 1.55 and below.
This issue affects SOPlanning version 1.55 and below.
Basic Information
ID
CVE-2026-40547
Source
CERT-PL
Published
Jun 1, 2026 at 09:04
Affected Product
Vendor
SOPlanning
Product
SOPlanning
Affected Versions
SOPlanning SOPlanning 0