Command Execution Vulnerability in DIRAC Software Framework
CVE-2026-45579

9.9CRITICAL

Key Information:

Vendor

Diracgrid

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-45579?

The DIRAC Software Framework is susceptible to a command execution vulnerability due to improper handling of user input in the RequestManagementSystem. An authenticated user can exploit this vulnerability by sending crafted grouping attributes, leading to the execution of arbitrary Python code on the server. This can result in exposure of sensitive configuration files, database credentials, and other critical information, effectively compromising the integrity of the DIRAC system. The issue is addressed in versions 8.0.79, 9.0.22, and 9.1.10.

Affected Version(s)

DIRAC >= 6r0, < 8.0.79 < 6r0, 8.0.79

DIRAC >= 9.0.0a1, < 9.0.22 < 9.0.0a1, 9.0.22

DIRAC >= 9.1.0, < 9.1.10 < 9.1.0, 9.1.10

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.