AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-62730

HIGH · CVSS 8.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-11-20 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. Exploitation may require the attacker to be authenticated.

CVE
CVE-2025-62730
Severity
HIGH
CVSS
8.8
EPSS
0.29%

Original NVD Description

SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to modify permissions of users. However, they are able to assign administrative permissions to any user including themselves. This allow a malicious authenticated attacker with this role to escalate to admin privileges. This issue affects both Bulk Update functionality and regular edition of user's right and privileges. This issue was fixed in version 1.55.

Related CVEs

Other vulnerabilities affecting the same vendor(s)