Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92379.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-92379
Upstream
  • CVE-2026-58479
Published
2026-07-14T15:17:06Z
Modified
2026-09-20T05:32:18Z
Summary
CVE-2026-58479 affecting package sip 4.19.25-13
Details

Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_control plugin that allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands by storing a malicious payload via the plugin's HTTP endpoint. Attackers can trigger execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor', to achieve arbitrary command execution on the underlying host.

References

Affected packages

Azure Linux:3 / sip

Package

Name
sip
Purl
pkg:rpm/azure-linux/sip

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
4.19.25-13

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92379.json"