<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Dolusoft Software Technologies - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/dolusoft-software-technologies/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 17 Aug 2026 14:47:08 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/dolusoft-software-technologies/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Missing Authorization Vulnerability in Dolusoft Sonlogger</title><link>https://feed.craftedsignal.io/briefs/2026-08-sonlogger-auth-bypass/</link><pubDate>Mon, 17 Aug 2026 14:47:08 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-sonlogger-auth-bypass/</guid><description>An unauthenticated access control vulnerability (CVE-2026-16471) in Dolusoft Sonlogger allows remote attackers to bypass ACLs and access restricted functionality.</description><content:encoded><![CDATA[<p>Dolusoft Software Technologies Sonlogger versions 6.6.6 through 6.7.4.7 contain a missing authorization vulnerability, tracked as CVE-2026-16471. This security flaw stems from insufficient enforcement of access control lists (ACLs) within the application's functionality. Because the vulnerability is exploitable without authentication, remote, unauthenticated attackers can leverage this defect to interact with sensitive features or internal endpoints of the Sonlogger platform that should otherwise be restricted. This exposure poses a significant risk to data confidentiality, as attackers may gain unauthorized access to logs, configurations, or administrative functions. The vulnerability was reported by the Computer Emergency Response Team of the Republic of Turkey. Organizations utilizing Sonlogger within the affected version range are urged to upgrade to version 6.7.4.8 or later to mitigate the risk of unauthorized access.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify internet-facing instances of Sonlogger.</li>
<li>Attacker probes the application to determine the version number and target reachable endpoints.</li>
<li>Attacker identifies an endpoint or function that is not properly constrained by server-side authorization checks.</li>
<li>Attacker crafts a specific HTTP request targeting the exposed functionality.</li>
<li>The application fails to validate the user session or authorization token for the requested operation.</li>
<li>The application processes the request and executes the privileged function.</li>
<li>Attacker extracts sensitive data, modifies configurations, or performs other unauthorized actions permitted by the vulnerable endpoint.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-16471 enables unauthenticated remote attackers to bypass authorization controls, potentially leading to unauthorized data exfiltration or administrative manipulation of the Sonlogger platform. This vulnerability is rated with a CVSS v3.1 base score of 7.5, indicating a high impact on confidentiality.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade all instances of Sonlogger to version 6.7.4.8 or newer to resolve the missing authorization flaw identified in CVE-2026-16471.</li>
<li>Audit access logs for abnormal requests to administrative or management endpoints originating from unauthorized source IP addresses.</li>
<li>Restrict network access to Sonlogger management interfaces, ensuring they are not exposed to the public internet unless required.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>