CVE-2026-40547

SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow reading and executing files previously added through the backup functionality. Critically, due to CVE-2026-40543 (Missing Authorization), any backup file can be read by any (unauthorized) user. This issue affects SOPlanning version 1.55 and below.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-06-01 09:16

Updated : 2026-07-22 07:10


NVD link : CVE-2026-40547

Mitre link : CVE-2026-40547

CVE.ORG link : CVE-2026-40547


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')