# SOPlanning flaws chain to unauthenticated RCE

Published: 2026-06-01 · Severity: medium
Canonical: https://vorant.io/reports/dd17e75f-0d3d-57dd-85b4-01b076029fdb/soplanning-flaws-chain-to-unauthenticated-rce

> Seven vulnerabilities in SOPlanning ≤1.55, including unauthenticated backup access and SQL injection, can be chained to achieve remote code execution.

CERT Polska coordinated disclosure of seven vulnerabilities in the open-source project management tool SOPlanning affecting version 1.55 and earlier. The most severe issue, CVE-2026-40543, allows an unauthenticated attacker to directly query backup endpoints and download database backups containing usernames, password hashes, and a config.csv file with additional sensitive data. Separately, CVE-2026-40546 exposes SQL injection across multiple endpoints and parameters, potentially giving an attacker with low privileges full database control.

The disclosure also details a path traversal flaw (CVE-2026-40547) and a file-upload weakness that skips extension verification (CVE-2026-40548), which when chained together allow an authenticated attacker to upload and execute arbitrary files, including PHP scripts, on the server. Because CVE-2026-40543 removes the authorization check on backup retrieval, this chain can effectively be exploited by an unauthenticated attacker to achieve remote code execution. Additional stored and reflected XSS issues (CVE-2026-40544, CVE-2026-40545) and a CSRF vulnerability in group management endpoints (CVE-2026-40549) round out the report.

No evidence of in-the-wild exploitation is mentioned; this is a coordinated vulnerability disclosure credited to researcher Łukasz Jaworski. Organizations running SOPlanning should apply vendor patches once available and restrict access to backup functionality in the interim.

## Mentioned in this report

- Vulnerabilities: CVE-2026-40543, CVE-2026-40544, CVE-2026-40545, CVE-2026-40546, CVE-2026-40547, CVE-2026-40548, CVE-2026-40549

Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-40543

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/dd17e75f-0d3d-57dd-85b4-01b076029fdb/soplanning-flaws-chain-to-unauthenticated-rce.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
