CVE-2026-40548
Deferred Deferred - Pending Action
SOPlanning File Upload Path Traversal Vulnerability

Publication date: 2026-06-01

Last updated on: 2026-06-01

Assigner: CERT.PL

Description
SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate user.csv file alongside a malicious file, which is extracted on the server. When combined with CVE-2026-40547 (Path Traversal), the malicious file (e.g., a PHP script) can be placed in a web-accessible location and executed via the browser. This issue affects SOPlanning version 1.55 and below.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-01
Generated
2026-06-21
AI Q&A
2026-06-01
EPSS Evaluated
2026-06-20
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
soplanning soplanning to 1.55 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in SOPlanning version 1.55 and below, where the software does not verify the extension of uploaded files during the backup functionality. An authenticated attacker can upload a crafted ZIP archive containing both a legitimate user.csv file and a malicious file. The malicious file is extracted on the server.

When this vulnerability is combined with CVE-2026-40547, which is a path traversal vulnerability, the attacker can place the malicious file (such as a PHP script) into a web-accessible location on the server. This allows the attacker to execute the malicious script through a web browser.

Impact Analysis

This vulnerability can allow an authenticated attacker to execute arbitrary code on the server by uploading and executing malicious files. This can lead to unauthorized access, data compromise, server control, and potentially further exploitation of the system.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-40548. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart