CVE-2026-58477

HIGH

Sustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters

Title source: cna
STIX 2.1

Description

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such as the passphrase and listening port, and can also achieve the same result through cross-site request forgery due to the absence of adequate request validation.

References (2)

Core 2
Core References
Exploit technical-description exploit
Zero Science Lab Advisory (ZSL-2026-5997)
https://www.zeroscience.mk/#/advisories/ZSL-2026-5997

Scores

CVSS v3 8.2
EPSS 0.0036
EPSS Percentile 28.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-915
Status published
Products (2)
Dan-in-CA/SIP < 5.2.16
dan-in-ca/sustainable_irrigation_platform < 5.2.16
Published Jul 14, 2026
Tracked Since Jul 14, 2026