Command Execution Vulnerability in DIRAC Software Framework
CVE-2026-45579
9.9CRITICAL
What is CVE-2026-45579?
The DIRAC Software Framework is susceptible to a command execution vulnerability due to improper handling of user input in the RequestManagementSystem. An authenticated user can exploit this vulnerability by sending crafted grouping attributes, leading to the execution of arbitrary Python code on the server. This can result in exposure of sensitive configuration files, database credentials, and other critical information, effectively compromising the integrity of the DIRAC system. The issue is addressed in versions 8.0.79, 9.0.22, and 9.1.10.
Affected Version(s)
DIRAC >= 6r0, < 8.0.79 < 6r0, 8.0.79
DIRAC >= 9.0.0a1, < 9.0.22 < 9.0.0a1, 9.0.22
DIRAC >= 9.1.0, < 9.1.10 < 9.1.0, 9.1.10
