PT-2026-58048 · Sustainable Irrigation Platform+1 · Cli Control+1

·

CVE-2026-58479

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sustainable Irrigation Platform (SIP) versions prior to 5.2.17
Description An issue exists in the optional cli control plugin that allows unauthenticated attackers or those using cross-site request forgery to execute arbitrary operating-system commands. This is achieved by storing a malicious payload via the plugin's HTTP endpoint. Execution is triggered when the associated irrigation station is activated, exploiting the lack of passphrase protection or the use of the default passphrase opendoor to run commands on the host.
Recommendations Update Sustainable Irrigation Platform (SIP) to version 5.2.17 or later. As a temporary mitigation, disable the cli control plugin.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92379
CVE-2026-58479

Affected Products

Sustainable Irrigation Platform
Cli Control