CVE-2026-50644
Deferred Deferred - Pending Action

SQL Injection in SOPlanning Audit Configuration

Vulnerability report for CVE-2026-50644, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-09

Last updated on: 2026-07-09

Assigner: CERT.PL

Description

SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user). This issue was fixed in version 1.56.01.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-09
Last Modified
2026-07-09
Generated
2026-07-15
AI Q&A
2026-07-09
EPSS Evaluated
2026-07-14
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
soplanning soplanning to 1.56.01 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50644 is a SQL injection vulnerability found in the SOPlanning software. It occurs in the audit retention configuration where an attacker who has parameters_all permissions can inject malicious SQL commands into the audit configuration form.

These injected SQL commands are then saved and executed when the audit functionality is accessed by either the attacker or another user.

This vulnerability affects all versions of SOPlanning prior to version 1.56.01, where it has been fixed.

Impact Analysis

This vulnerability allows an attacker with sufficient permissions to execute arbitrary SQL commands within the SOPlanning audit configuration.

The impact includes potential unauthorized data access, data manipulation, or corruption when the audit functionality is accessed.

Since the execution can be triggered by any user accessing the audit functionality, it could lead to broader compromise or data integrity issues within the system.

Mitigation Strategies

To mitigate this vulnerability, you should upgrade SOPlanning to version 1.56.01 or later, where the SQL injection issue in the audit retention configuration has been fixed.

Additionally, restrict or review permissions for users with parameters_all rights to limit the risk of exploitation.

Compliance Impact

The vulnerability allows an attacker with parameters_all rights to inject SQL commands into the audit retention configuration, potentially compromising the integrity and confidentiality of audit data.

Since audit logs are critical for compliance with standards such as GDPR and HIPAA, which require secure and tamper-proof logging of access and changes, this SQL injection vulnerability could undermine compliance by allowing unauthorized modification or manipulation of audit records.

Therefore, exploitation of this vulnerability may lead to violations of regulatory requirements related to data integrity, accountability, and auditability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50644. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart