Description
Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.
Published: 2026-08-17
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in Dolusoft Software Technologies’ Sonlogger application, classified as CWE‑862. It allows functions that should be governed by an access control list to be invoked without proper permission checks. Based on the description, it is inferred that an attacker who can send requests to the application could trigger these exposed functions, potentially gaining access to sensitive data, altering configuration settings, or executing actions reserved for privileged users, thereby compromising confidentiality, integrity, or availability.

Affected Systems

Affected versions of Sonlogger include all releases from v6.6.6 up to, but not including, v6.7.4.8. The issue exists on the standard installation of Dolusoft Software Technologies Sonlogger, and any deployment using a version in this range remains vulnerable until the vendor releases a fixed build.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed. The likely attack vector is remote request to the application’s exposed endpoints; however, the lack of a documented exploitation technique means the exact likelihood of a real-world attack remains uncertain. Environments in which Sonlogger is exposed to external users or where default ACL configurations are not hardened may face a higher risk level.

Generated by OpenCVE AI on August 17, 2026 at 14:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Sonlogger to version 6.7.4.8 or later to apply the vendor‑supplied fix for the missing authorization checks.
  • Review and enforce ACL settings on all protected functions, ensuring that only authorized roles can invoke sensitive endpoints.
  • Disable or protect any unused or publicly exposed endpoints that do not require authentication, and monitor logs for unauthorized access attempts.

Generated by OpenCVE AI on August 17, 2026 at 14:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Dolusoft Software Technologies Sonlogger allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Sonlogger: from v6.6.6 before 6.7.4.8.
Title Broken Access Control in Dolusoft Software's Sonlogger
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-17T14:11:52.744Z

Reserved: 2026-07-21T13:47:17.440Z

Link: CVE-2026-16471

cve-icon Vulnrichment

Updated: 2026-08-17T14:11:49.069Z

cve-icon NVD

Status : Received

Published: 2026-08-17T14:20:20.147

Modified: 2026-08-17T14:20:20.147

Link: CVE-2026-16471

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:00:08Z

Weaknesses