Description
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authenticated caller-controlled groupingAttribute to RequestManagementSystem/DB/RequestDB.py getRequestCountersWeb. An unrecognized value is resolved against the Request object and evaluated as Python code, allowing a crafted dunder attribute expression to reach operating-system functions and execute commands as the account running the DIRAC services. Successful exploitation can expose dirac.cfg, database passwords, stored proxies, and tokens, fully compromise the DIRAC system, and allow alteration of local log evidence. This issue is fixed in versions 8.0.79, 9.0.22, and 9.1.10.
Published: 2026-09-15
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in an eval call that processes an untrusted groupingAttribute passed by an authenticated caller to the export_getRequestCountersWeb function in the RequestManager. The unrecognized value is resolved against the Request object and evaluated as raw Python code, enabling a crafted expression to invoke operating‑system functions and execute commands as the user running the DIRAC services. An attacker can therefore read or modify the dirac.cfg file, obtain database passwords, stored proxies, and tokens, fully compromise the DIRAC system, and alter local log evidence. The flaw is a classic use of eval on untrusted data (CWE‑95).

Affected Systems

DIRACGrid’s DIRAC interware, versions older than 8.0.79, 9.0.22, and 9.1.10. All releases prior to those patch releases contain the vulnerable code. Updated releases 8.0.79 or newer, 9.0.22 or newer, and 9.1.10 or newer contain the fix that removes the eval path.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity. The EPSS score is < 1%, indicating a low probability of exploitation today, yet the absence of a public exploit does not reduce the risk to systems that remain on vulnerable versions. The attack requires an authenticated user to invoke the RequestManager endpoint; once authenticated, the attacker can inject any Python expression that the service will evaluate. If successfully exploited, the attacker can read sensitive files, exfiltrate credentials, and alter local log evidence, effectively taking over the DIRAC deployment.

Generated by OpenCVE AI on September 20, 2026 at 14:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade DIRAC to release 8.0.79 or newer, 9.0.22 or newer, or 9.1.10 or newer.
  • Execute the upgrade under a least‑privilege user account and consider restricting execution privileges on the service with SELinux or AppArmor.
  • After the upgrade, audit system logs for signs of command execution and regenerate any compromised credentials, database passwords, proxies, and tokens.

Generated by OpenCVE AI on September 20, 2026 at 14:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9jpv-c7p4-997x DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input
History

Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Diracgrid
Diracgrid dirac
Vendors & Products Diracgrid
Diracgrid dirac

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, the RequestManagementSystem/Service/ReqManagerHandler.py export_getRequestCountersWeb function passes an authenticated caller-controlled groupingAttribute to RequestManagementSystem/DB/RequestDB.py getRequestCountersWeb. An unrecognized value is resolved against the Request object and evaluated as Python code, allowing a crafted dunder attribute expression to reach operating-system functions and execute commands as the account running the DIRAC services. Successful exploitation can expose dirac.cfg, database passwords, stored proxies, and tokens, fully compromise the DIRAC system, and allow alteration of local log evidence. This issue is fixed in versions 8.0.79, 9.0.22, and 9.1.10.
Title DIRAC: RCE in RequestManager due to eval on untrusted input
Weaknesses CWE-95
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T18:48:26.192Z

Reserved: 2026-05-12T19:00:14.600Z

Link: CVE-2026-45579

cve-icon Vulnrichment

Updated: 2026-09-15T18:45:05.436Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:21.427

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-45579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:00:11Z

Weaknesses
  • CWE-95

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')