CVE Feed

    Dashboard / CVE / CVE-2026-60114

    CVE-2026-60114

    Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the lack of key validation in the JSON restore process, combined with the absence of a required passphrase in the default configuration or the default passphrase 'opendoor', to write arbitrary JSON files outside the intended data directory.

    Published:Jul 14, 2026
    Last Modified:Jul 27, 2026
    EPS:Jul 14, 2026
    EPSS Score:0.00369
    CVSS Score:7.5

    Affected Products

    Vendor
    Dan-in-ca
    Product
    Sip

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High