Junglewise Threat Intelligence

CVE-2026-58477: Dan-in-CA SIP mass assignment in configuration settings

CVE-2026-58477 · Severity: high · CVSS 8.2 · Published 2026-07-14

Technologies: Dan-in-CA Sustainable Irrigation Platform. Vendors: Dan-in-CA.

Executive brief

The Sustainable Irrigation Platform (SIP), a system used for managing irrigation infrastructure, contains a security flaw that allows unauthorized individuals to change critical system settings. By sending specially crafted web requests, an attacker could modify the device's password or change the communication ports it uses to listen for commands. This could lead to a complete loss of control over the irrigation system, potential service outages, or unauthorized access to the management interface.

Technical details

A mass assignment vulnerability (CWE-915) exists in the Sustainable Irrigation Platform (SIP) through version 5.2.16. The application fails to properly filter or restrict HTTP parameters, allowing unauthenticated remote attackers to overwrite sensitive internal configuration attributes by supplying arbitrary parameter names in HTTP requests. Specifically, attackers can manipulate critical values such as the system passphrase and the service listening port. Additionally, the lack of adequate request validation makes the system susceptible to achieving the same result via Cross-Site Request Forgery (CSRF). As of the advisory date, no specific patch version has been confirmed, though the vulnerability is documented through version 5.2.16.

Affected products

  • Dan-in-CA SIP (Sustainable Irrigation Platform) through 5.2.16

Timeline

  • 2026-07-14: advisory: Initial disclosure by VulnCheck and Zero Science Lab
  • 2026-07-14: disclosed: CVE-2026-58477 published to NVD

References

Related threats