CVE-2026-40543
Deferred Deferred - Pending Action
Unauthenticated Backup Access in SOPlanning

Publication date: 2026-06-01

Last updated on: 2026-06-01

Assigner: CERT.PL

Description
SOPlanning does not enforce authorization for backup functionalities.Β An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases with usernames and password hashes, as well as the config.csv file, which includes additional sensitive information. This issue affects SOPlanning version 1.55 and below.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-01
Generated
2026-06-21
AI Q&A
2026-06-01
EPSS Evaluated
2026-06-20
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
soplanning soplanning to 1.55 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Compliance Impact

This vulnerability allows an unauthenticated attacker to access backup archives containing user databases with usernames and password hashes, as well as sensitive configuration files. Such unauthorized access to personal and sensitive data can lead to violations of data protection regulations like GDPR and HIPAA, which require strict controls on access to personal and sensitive information.

Failure to enforce authorization on backup functionalities compromises confidentiality and integrity of user data, potentially resulting in non-compliance with these standards that mandate protection against unauthorized data access.

Executive Summary

This vulnerability exists in SOPlanning version 1.55 and below, where the software does not enforce authorization for its backup functionalities.

As a result, an unauthenticated attacker can directly access backup-related endpoints without any restrictions.

This allows the attacker to retrieve backup archives that contain sensitive data such as user databases with usernames and password hashes, as well as the config.csv file which holds additional sensitive information.

Impact Analysis

The vulnerability can have severe impacts because it allows unauthorized access to sensitive data.

  • Exposure of user databases including usernames and password hashes, which could lead to credential compromise.
  • Access to configuration files containing sensitive information that could be used to further exploit the system.

Overall, this could lead to unauthorized data disclosure, potential account takeovers, and further system compromise.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40543. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart