CVE-2026-60114 Details
Description
Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the lack of key validation in the JSON restore process, combined with the absence of a required passphrase in the default configuration or the default passphrase 'opendoor', to write arbitrary JSON files outside the intended data directory.
A path traversal vulnerability has been identified in the Sustainable Irrigation Platform (SIP) in versions through 5.2.16. This vulnerability allows attackers with access to the restore feature to write files to arbitrary locations. Exploitation is achieved by uploading crafted JSON backup files containing unvalidated keys that are used to create file paths. The vulnerability arises from the lack of key validation in the JSON restore process, coupled with the absence of a required passphrase in the default configuration, or the use of 'opendoor' as the default passphrase. As a result, attackers can write arbitrary JSON files outside the designated data directory.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.vulncheck.com/advisories/sustainable-irrigation-platform-path-traversal-via-json-backup-restore | [email protected] | Third Party Advisory |
| https://www.zeroscience.mk/#/advisories/ZSL-2026-5996 | [email protected] | ExploitThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dan-in-ca sustainable irrigation platform | <= 5.2.16 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | Initial Analysis | [email protected] |
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |