PT-2026-103948 · Djehuty · Djehuty
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
djehuty versions prior to 26.3.2
Description
An authenticated depositor can perform a SPARQL injection—a technique used to manipulate queries in a SPARQL endpoint—into a state-modifying (DELETE/INSERT) query. By providing a crafted session name, an attacker can write or delete arbitrary triples within the RDF store. Since the RDF store is shared across all accounts and datasets, this allows for an integrity compromise of the entire repository's metadata. A logged-in account is required, which is easily obtained in typical deployments through self-registration via ORCID/SAML.
Recommendations
Update to version 26.3.2.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Djehuty