CVE-2026-50644
HIGHSQL Injection in SOPlanning Audit Retention Configuration
Title source: cnaDescription
SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user). This issue was fixed in version 1.56.01.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/en/posts/2026/07/CVE-2026-50644
Product product
https://www.soplanning.org/en/
Scores
CVSS v4
8.6
EPSS
0.0028
EPSS Percentile
19.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-89
Status
published
Products (1)
SOPlanning/SOPlanning
< 1.56.01
Published
Jul 09, 2026
Tracked Since
Jul 09, 2026