CVE-2025-62730

HIGH

soplanning < 1.55.00 - Authenticated Privilege Escalation via User Management Tab

Title source: llm
STIX 2.1

Description

SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges. This issue was fixed in version 1.55.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/en/posts/2025/11/CVE-2025-62293

Scores

CVSS v3 8.8
EPSS 0.0026
EPSS Percentile 16.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-863
Status published
Products (1)
soplanning/soplanning < 1.55.00
Published Nov 20, 2025
Tracked Since Feb 18, 2026