PT-2026-60075 · Dirac · Dirac

CVE-2026-45579

·

Published

2026-07-13

·

Updated

2026-07-23

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DIRAC versions prior to 8.0.79 DIRAC versions prior to 9.0.22 DIRAC versions prior to 9.1.10
Description Remote code execution is possible in RequestManager because the export getRequestCountersWeb() function passes parameters directly to the database instance. When the groupingAttribute variable is unrecognized, the system prepends Request. to it and passes the result into an eval() call. An authenticated user can provide a dunder string applicable to the Request object to access functions in the os module and execute commands in the server context. This can lead to a full system compromise, including access to the dirac.cfg file, database passwords, and stored proxies and tokens. Additionally, attackers may be able to remove evidence of the exploit from local logs.
Recommendations Update to version 8.0.79 or later. Update to version 9.0.22 or later. Update to version 9.1.10 or later.

Fix

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45579
GHSA-9JPV-C7P4-997X
PYSEC-2026-3462

Affected Products

Dirac