SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases with usernames and password hashes, as well as the config.csv file, which includes additional sensitive information.
This issue affects SOPlanning version 1.55 and below.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-01 09:16
Updated : 2026-07-22 07:10
NVD link : CVE-2026-40543
Mitre link : CVE-2026-40543
CVE.ORG link : CVE-2026-40543
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
