Description
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datasets value to DatasetManager.py __checkDataset, where datasetName is interpolated into an FC_MetaDatasets SQL query without parameterization. The injected query can control the returned MetaQuery value, which is passed to Python eval and permits command execution as the account running the DIRAC services. Successful exploitation can expose dirac.cfg, database passwords, stored proxies, and tokens, fully compromise the DIRAC system, and allow alteration of local log evidence. This issue is fixed in versions 8.0.79, 9.0.22, and 9.1.10.
Published: 2026-09-15
Score: 9.9 Critical
EPSS: 1.2% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Prior to versions 8.0.79, 9.0.22, and 9.1.10, the DataManagementSystem/Service/FileCatalogHandler.py checkDataset function forwards an authenticated caller‑controlled datasets value to DatasetManager.py __checkDataset, where the datasetName is interpolated into an FC_MetaDatasets SQL query without parameterization (CWE‑89). The injected query can manipulate the returned MetaQuery value, which is then passed to Python eval (CWE‑95) and permits command execution as the account running the DIRAC services. Successful exploitation can expose dirac.cfg, database passwords, stored proxies, and tokens, fully compromise the DIRAC system, and allow alteration of local log evidence, effectively granting an attacker full control over the system.

Affected Systems

DIRACGrid:DIRAC interware, specifically the DataManagement System’s FileCatalogHandler component, is affected. The vulnerability resides in all releases before 8.0.79, 9.0.22, and 9.1.10.

Risk and Exploitability

The CVSS score of 9.9 marks the flaw as critical. Exploitation requires an authenticated session to the service, so attackers need legitimate access or escalating privileges. The EPSS score of <1% indicates a low but nonzero probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The combination of unsanitized SQL with eval renders it highly exploitable within a compromised or authorized deployment.

Generated by OpenCVE AI on September 20, 2026 at 15:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade DIRAC to version 8.0.79, 9.0.22, or 9.1.10, which remove the vulnerable interpolation and eval usage.
  • If a full upgrade cannot be applied immediately, replace or patch the vulnerable code paths in FileCatalogHandler.py and DatasetManager.py so that the dataset name is properly parameterized and eval is removed.
  • If patching is delayed, restrict network access to the FileCatalogHandler endpoint so that only trusted internal hosts can reach it, mitigating potential exploitation.

Generated by OpenCVE AI on September 20, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-m4m7-4cw8-62j6 DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval
History

Tue, 15 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Diracgrid
Diracgrid dirac
Vendors & Products Diracgrid
Diracgrid dirac

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, DataManagementSystem/Service/FileCatalogHandler.py checkDataset forwards an authenticated caller-controlled datasets value to DatasetManager.py __checkDataset, where datasetName is interpolated into an FC_MetaDatasets SQL query without parameterization. The injected query can control the returned MetaQuery value, which is passed to Python eval and permits command execution as the account running the DIRAC services. Successful exploitation can expose dirac.cfg, database passwords, stored proxies, and tokens, fully compromise the DIRAC system, and allow alteration of local log evidence. This issue is fixed in versions 8.0.79, 9.0.22, and 9.1.10.
Title DIRAC: RCE in FileCatalog DatasetManager via SQL injection + eval
Weaknesses CWE-89
CWE-95
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T18:44:14.827Z

Reserved: 2026-07-10T18:25:21.467Z

Link: CVE-2026-61667

cve-icon Vulnrichment

Updated: 2026-09-15T18:44:09.585Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:27.050

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-61667

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T15:45:17Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

  • CWE-95

    Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')