SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-58477

HIGH · CVSS 8.2 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

The Sustainable Irrigation Platform (SIP) versions up to 5.2.16 are vulnerable to a mass assignment flaw that enables unauthenticated attackers to overwrite critical configuration settings via arbitrary HTTP parameters. This vulnerability can lead to unauthorized access to sensitive values, including passphrases and listening ports, and is further exacerbated by insufficient request validation, allowing for cross-site request forgery attacks. Organizations using this platform should prioritize remediation to mitigate the risk of unauthorized configuration changes and potential system compromise.

CVE
CVE-2026-58477
Severity
HIGH
CVSS
8.2
EPSS
0.36%

Original NVD Description

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a mass assignment vulnerability that allows unauthenticated attackers to overwrite sensitive configuration settings by supplying arbitrary parameter names in HTTP requests. Attackers can manipulate parameters corresponding to sensitive values such as the passphrase and listening port, and can also achieve the same result through cross-site request forgery due to the absence of adequate request validation.

Related CVEs

Other vulnerabilities affecting the same vendor(s)