CVE-2026-82307: Multiple Vulnerabilities in Dolusoft Software's SOPLOG
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection.
This issue affects SOPLOG: before Soplog 2026.9.4.1.
Affected Software
Event History
Frequently Asked Questions
Which SOPLOG versions are affected?
SOPLOG versions before 2026.9.4.1 are affected. The provided information does not state whether version 2026.9.4.1 or later has been independently verified as fixed.
Does exploitation require authentication or user interaction?
The vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required. This means an unauthenticated remote attacker may be able to exploit the SQL injection issue if they can reach a vulnerable SOPLOG instance.
What is the potential impact of successful exploitation?
The severity vector indicates high impact to confidentiality, integrity, and availability. Successful exploitation could therefore expose, alter, or disrupt data and services accessible through the affected application.