External risk intelligence

DIRAC SQL Injection and Command Execution Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-61667

DIRAC is a specialized framework for distributed computing. While network-reachable, these services are typically deployed within private research or institutional compute environments rather than being exposed as public internet-facing services. Public accessibility is possible in specific research collaborations, but it is not a standard or universal deployment pattern.

SQL Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the DIRAC distributed computing framework could allow an authenticated user to execute commands on the system. This could expose sensitive credentials and system configurations, and allow an attacker to alter logs. The primary concern is confirming if DIRAC services are in use and assessing exposure.

  • Commands can be run by attackers on systems.
  • Sensitive credentials and system logs are at risk.
  • Confirm DIRAC usage and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could compromise the DIRAC system by exploiting a vulnerability in how it handles dataset names. After gaining authenticated access, an attacker could send a specially crafted dataset name that, when processed by the File Catalog, leads to a dangerous SQL query. This query is then evaluated by Python's `eval` function, allowing the attacker to execute commands on the server.

  • Authenticated access is required.
  • Malicious dataset name triggers code execution.
  • Full system compromise and data alteration.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in DIRAC's File Catalog Handler could allow an authenticated user to execute arbitrary commands on the DIRAC service. This could occur when the system processes user-supplied dataset names, potentially leading to the compromise of sensitive configuration files, credentials, and session tokens. When supported by the advisory, the system's integrity could be fully compromised, and log tampering may be possible.

  • Sensitive configuration and credentials.
  • Unparameterized SQL injection and eval.
  • Full system compromise and log alteration.

Operational Fix

Recommended remediation, mitigation, and detection steps

The DIRAC distributed computing framework is susceptible to critical vulnerabilities. Initial actions should focus on identifying all DIRAC instances, confirming their exposure and business criticality, and locating the accountable owners within platform or infrastructure teams. A risk-based remediation plan, potentially involving vendor coordination for updates or the implementation of temporary controls, should follow.

  • Platform or infrastructure teams own resolution.
  • Verify DIRAC instance exposure and criticality.
  • Plan vendor-coordinated updates or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the DIRAC framework used for?

DIRAC is an interware platform designed to manage distributed computing tasks. It acts as a framework that orchestrates workloads, data, and resources across various computing grids, often used by scientific research collaborations to handle massive datasets and computational workflows.

How does CVE-2026-61667 create a security risk?

This vulnerability involves SQL injection and improper code evaluation (CWE-89 and CWE-95). Because the software incorrectly handles user-supplied dataset names in a database query and subsequently passes that result to a Python eval function, an attacker can manipulate the process to execute arbitrary system commands.

Do I need unauthenticated access to trigger this bug?

No. Successful exploitation requires the attacker to have authenticated access to the DIRAC system. The issue is triggered specifically when a caller provides a crafted dataset name that the system processes; simply visiting or interacting with the service anonymously will not initiate this command execution path.

Is my DIRAC installation at risk if it is internal?

While Halo Surface Signal notes that DIRAC services are often kept in private research environments, they remain reachable over a network. Any authenticated user with access to the service—even within an internal network—could potentially leverage this flaw. You should evaluate access controls to see who can reach your instances.

When should I update DIRAC to address this?

You should prioritize updates as soon as you identify your DIRAC instances. The vulnerability is resolved in versions 8.0.79, 9.0.22, and 9.1.10. Coordination with your infrastructure or platform teams is the recommended first step to verify your current version and apply the appropriate vendor-provided fix.

References