CVE-2026-50644

HIGH

SQL Injection in SOPlanning Audit Retention Configuration

Title source: cna
STIX 2.1

Description

SOPlanning is vulnerable to SQL injection in the audit retention configuration. An attacker holding parameters_all rights can inject SQL commands into the audit configuration form which is then saved. The execution is triggered when the audit functionality is accessed (by the attacker or another user). This issue was fixed in version 1.56.01.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/en/posts/2026/07/CVE-2026-50644

Scores

CVSS v4 8.6
EPSS 0.0028
EPSS Percentile 19.9%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
SOPlanning/SOPlanning < 1.56.01
Published Jul 09, 2026
Tracked Since Jul 09, 2026