Junglewise Threat Intelligence

CVE-2026-60114: Dan-in-CA SIP path traversal in JSON backup restore

CVE-2026-60114 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Dan-in-CA Sustainable Irrigation Platform. Vendors: Dan-in-CA.

Executive brief

The Sustainable Irrigation Platform (SIP), a system used for managing irrigation operations, contains a security flaw in its backup restoration process. An attacker can exploit this to write malicious files to any location on the system's storage. This could lead to a complete system takeover, unauthorized modification of irrigation schedules, or disruption of agricultural operations.

Technical details

A path traversal vulnerability exists in the Sustainable Irrigation Platform (SIP) through version 5.2.16. The flaw is located in the restore functionality, where the application fails to validate keys within uploaded JSON backup files used to construct file paths. An attacker can provide crafted JSON files with traversal sequences (e.g., ../) to write files outside the intended data directory. This is further exacerbated by a default configuration that either lacks a passphrase or uses the default passphrase 'opendoor'. Successful exploitation allows an unauthenticated remote attacker to achieve arbitrary file writes on the underlying filesystem.

Affected products

  • Dan-in-CA SIP (Sustainable Irrigation Platform) through 5.2.16

Timeline

  • 2026-07-14: advisory: Initial disclosure by VulnCheck and Zero Science Lab
  • 2026-07-14: disclosed

References

Related threats