PT-2026-58049 · Unknown · Sustainable Irrigation Platform

·

CVE-2026-60114

·

Published

2026-07-14

·

Updated

2026-07-14

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Sustainable Irrigation Platform (SIP) versions prior to 5.2.17
Description An issue exists in the restore functionality where the system fails to validate keys within uploaded JSON backup files used to construct file paths. This allows an attacker to perform path traversal, which is a method of accessing files and directories that are stored outside the web root folder. By exploiting this lack of validation, and leveraging either the default passphrase 'opendoor' or the absence of a required passphrase in the default configuration, an attacker can write arbitrary JSON files to unauthorized locations on the system.
Recommendations Update Sustainable Irrigation Platform (SIP) to version 5.2.17 or later. Change the default passphrase 'opendoor' to a strong, unique passphrase. Ensure that a passphrase is required for the restore functionality in the system configuration.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92370
CVE-2026-60114

Affected Products

Sustainable Irrigation Platform