Junglewise Threat Intelligence

DIRAC SQL injection and improper access control in PilotManager

Severity: high · CVSS 8.5 · Published 2026-07-13

Technologies: DIRACGrid DIRAC.

Executive brief

DIRAC, a software framework for distributed computing, contains security flaws in its PilotManager service. These flaws allow any authenticated user to view or delete computing jobs belonging to other users. Additionally, a database vulnerability could allow an attacker to manipulate or extract sensitive information from the system's database.

Technical details

The DIRAC PilotManager service suffers from two primary vulnerabilities: SQL injection (CWE-89) and improper access control (CWE-284). Several functions in PilotManagerHandler.py and PilotAgentsDB.py pass user-supplied parameters directly to the database layer without proper escaping or parameter substitution. Furthermore, the access control configuration for PilotManager is set to 'authenticated', which fails to enforce granular permissions, allowing any logged-in user to perform administrative actions like deleting or reading the output of any pilot job. Attackers can exploit these issues via network requests to modify or extract database records. The issues are resolved in versions 8.0.79, 9.0.22, and 9.1.10.

Affected products

  • DIRACGrid DIRAC >= 6, < 8.0.79
  • DIRACGrid DIRAC >= 8.1.0a1, < 9.0.22
  • DIRACGrid DIRAC >= 9.1.0, < 9.1.10

Timeline

  • 2026-07-13: advisory
  • 2026-07-13: patched

References