CVE-2026-58477
HIGHSustainable Irrigation Platform 5.2.16 Mass Assignment via HTTP Parameters
Title source: cnaDescription
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such as the passphrase and listening port, and can also achieve the same result through cross-site request forgery due to the absence of adequate request validation.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Zero Science Lab Advisory (ZSL-2026-5997)
https://www.zeroscience.mk/#/advisories/ZSL-2026-5997
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/sustainable-irrigation-platform-mass-assignment-via-http-parameters
Scores
CVSS v3
8.2
EPSS
0.0036
EPSS Percentile
28.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-915
Status
published
Products (2)
Dan-in-CA/SIP
< 5.2.16
dan-in-ca/sustainable_irrigation_platform
< 5.2.16
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026