External risk intelligence

DIRAC Request Management System Code Injection Leads to Full System Compromise.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-45579

DIRAC is a distributed computing framework typically deployed within private research, scientific, or academic grid environments. While it involves network-reachable services and web-based management, these are generally intended for authenticated users within specific collaborative infrastructures rather than being exposed to the general public internet.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in the DIRAC distributed computing framework that could allow an authenticated user to execute arbitrary commands on the system. This could lead to a full compromise of the DIRAC system, exposing sensitive credentials and allowing for the alteration of logs. The main concern is confirming relevance and exposure within our specific DIRAC deployments.

  • System could be fully compromised.
  • Affects distributed computing framework services.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with access to the DIRAC system can manipulate the `export_getRequestCountersWeb` function by providing a specially crafted grouping attribute. This input is passed to a database function where an unrecognized value is interpreted as Python code, allowing the attacker to execute arbitrary commands on the server as the DIRAC service account. This can lead to the compromise of sensitive information like configuration files and credentials, full system control, and the ability to tamper with logs.

  • Requires authenticated access to DIRAC.
  • Triggered by a crafted grouping attribute input.
  • Risk of system compromise and data exposure.

Live Threat

Current exploitation, exposure, and threat context

An authenticated user could exploit a flaw in the DIRAC Request Management System to execute arbitrary commands on the underlying server. This could occur when an attacker provides a specially crafted grouping attribute to the `getRequestCountersWeb` function, causing it to evaluate Python code. When supported by the advisory, this could lead to the exposure of sensitive configuration files, credentials, and tokens.

  • System files and credentials at risk.
  • Malicious input to specific function.
  • Full system compromise and log alteration.

Operational Fix

Recommended remediation, mitigation, and detection steps

The DIRAC framework, used in distributed computing environments, has a critical vulnerability that allows for remote command execution. This issue likely impacts platform or infrastructure teams responsible for managing the DIRAC services. The immediate first step is to identify all DIRAC instances, confirm their exposure and criticality, and then assign ownership for remediation planning.

  • Platform or infrastructure teams own remediation.
  • Verify DIRAC instance exposure and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is DIRAC and how is it used?

DIRAC is an interware framework designed for distributed computing, often deployed in academic, scientific, and research grid environments. It manages complex workflows and computational tasks across distributed resources, acting as a middleware layer that helps orchestrate large-scale data processing and resource sharing among collaborative teams.

What does CVE-2026-45579 mean for DIRAC security?

This CVE identifies a code injection vulnerability, specifically categorized as CWE-95 (Improper Neutralization of Directives in Dynamically Evaluated Code). It occurs because the system incorrectly evaluates user-supplied input as Python code. If an attacker sends a malicious command string, the server treats it as a legitimate system instruction, enabling them to execute commands with the privileges of the DIRAC service account.

How can an attacker trigger this vulnerability?

An attacker must provide a specially crafted 'groupingAttribute' value to the export_getRequestCountersWeb function within the Request Management System. Because the system performs this evaluation on provided inputs, simply browsing the interface or interacting with non-request-related functions does not trigger the bug; the specific malicious input must be passed to this vulnerable processing chain.

Is my DIRAC deployment at risk?

According to Halo Surface Signal, DIRAC is usually deployed within private or academic research grids rather than being exposed to the general public internet. While the vulnerability requires authenticated access, any instance reachable over a network—internal or otherwise—should be considered a potential target if untrusted or compromised accounts exist within the environment.

What should I do to secure my DIRAC system?

The primary response is to update your DIRAC installation to version 8.0.79, 9.0.22, or 9.1.10, which contain the necessary fixes for this issue. Before patching, identify all running instances of DIRAC in your infrastructure, verify which versions are currently in use, and coordinate with your platform or infrastructure team to schedule the update and mitigate the risk of unauthorized command execution.

References