PT-2026-60112 · Dirac · Dirac
CVE-2026-61668
·
Published
2026-07-13
·
Updated
2026-07-23
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DIRAC versions prior to 8.0.79
DIRAC versions prior to 9.0.22
DIRAC versions prior to 9.1.10
Description
The initial wrapper script downloads the second stage pilot (
pilot.tar) and executes the contained script without verifying the web server's SSL certificate. Although a checksum is tested, the reference checksum file is downloaded via the same unvalidated channel. This lack of verification allows a man-in-the-middle attack to alter the second stage pilot code, potentially leading to the execution of arbitrary code within the pilot context, granting access to pilot proxies and credentials.Recommendations
Update to version 8.0.79 or later.
Update to version 9.0.22 or later.
Update to version 9.1.10 or later.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dirac