Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92370.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92370
Upstream
  • CVE-2026-60114
Published
2026-07-14T15:17:08Z
Modified
2026-08-29T05:25:22Z
Summary
CVE-2026-60114 affecting package sip 4.19.25-13
Details

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a path traversal vulnerability that allows attackers with access to the restore functionality to write files to arbitrary locations by uploading crafted JSON backup files with unvalidated keys used to construct file paths. Attackers can exploit the lack of key validation in the JSON restore process, combined with the absence of a required passphrase in the default configuration or the default passphrase 'opendoor', to write arbitrary JSON files outside the intended data directory.

References

Affected packages

Azure Linux:3 / sip

Package

Name
sip
Purl
pkg:rpm/azure-linux/sip

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
4.19.25-13

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92370.json"