Junglewise Threat Intelligence

CVE-2026-58476: Dan-in-CA Sustainable Irrigation Platform CSRF in administrative endpoints

CVE-2026-58476 · Severity: high · CVSS 8.1 · Published 2026-07-14

Technologies: Dan-in-CA Sustainable Irrigation Platform. Vendors: Dan-in-CA.

Executive brief

The Sustainable Irrigation Platform (SIP), a system used to manage automated irrigation, is vulnerable to an attack that could allow unauthorized users to take control of the device. By tricking a logged-in administrator into clicking a malicious link, an attacker can remotely reboot the device, delete irrigation programs, or install unauthorized software. This could lead to significant operational disruptions, such as crop damage due to failed irrigation or complete loss of device control.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Sustainable Irrigation Platform (SIP) through version 5.2.16. The application fails to implement CSRF token validation or origin verification for state-changing administrative actions performed via HTTP GET requests. An attacker can exploit this by luring an authenticated administrator to a malicious website that triggers these GET requests in the background. Impacted actions include disabling passphrases, rebooting the device, deleting programs, and installing plugins. Furthermore, the default configuration uses a known credential ('opendoor') and often lacks a required passphrase, increasing the risk of unauthorized access. No patch is currently specified in the advisory.

Affected products

  • Dan-in-CA SIP (Sustainable Irrigation Platform) through 5.2.16

Timeline

  • 2026-07-14: advisory: Initial disclosure by VulnCheck and Zero Science Lab

References

Related threats