VORANT. Threat Intelligence Sign in Get the full feed

SOPlanning flaws chain to unauthenticated RCE

medium vulnerability

Seven vulnerabilities in SOPlanning ≤1.55, including unauthenticated backup access and SQL injection, can be chained to achieve remote code execution.

CERT Polska coordinated disclosure of seven vulnerabilities in the open-source project management tool SOPlanning affecting version 1.55 and earlier. The most severe issue, CVE-2026-40543, allows an unauthenticated attacker to directly query backup endpoints and download database backups containing usernames, password hashes, and a config.csv file with additional sensitive data. Separately, CVE-2026-40546 exposes SQL injection across multiple endpoints and parameters, potentially giving an attacker with low privileges full database control.

The disclosure also details a path traversal flaw (CVE-2026-40547) and a file-upload weakness that skips extension verification (CVE-2026-40548), which when chained together allow an authenticated attacker to upload and execute arbitrary files, including PHP scripts, on the server. Because CVE-2026-40543 removes the authorization check on backup retrieval, this chain can effectively be exploited by an unauthenticated attacker to achieve remote code execution. Additional stored and reflected XSS issues (CVE-2026-40544, CVE-2026-40545) and a CSRF vulnerability in group management endpoints (CVE-2026-40549) round out the report.

No evidence of in-the-wild exploitation is mentioned; this is a coordinated vulnerability disclosure credited to researcher Łukasz Jaworski. Organizations running SOPlanning should apply vendor patches once available and restrict access to backup functionality in the interim.

Mentioned in this report

Vulnerabilities CVE-2026-40543CVE-2026-40544CVE-2026-40545CVE-2026-40546CVE-2026-40547CVE-2026-40548CVE-2026-40549

Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-40543

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free