CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-58479

Critical · CVSS 9.8

Sustainable Irrigation Platform (SIP) — Command Injection (OS Command Injection via CLI Control Plugin HTTP Endpoint)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-78

Description

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host.

Search profile — drives PoC discovery

Symbols cli_controlcli_control pluginopendoorirrigation stationpassphraseHTTP endpointcli_control endpoint
Keywords CVE-2026-58479Sustainable Irrigation PlatformSIP command injectioncli_control pluginSIP RCEirrigation platform exploitopendoor passphraseZSL-2026-5999SIP 5.2.16cli_control command injectionunauthenticated RCE SIPCSRF command injection irrigation
Versions: through 5.2.16

References

Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T06:30:20.000Z