CVE-2026-61668
- Gepubliceerd15 sep 2026
Beschrijving
DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1.10, WorkloadManagementSystem/Utilities/PilotWrapper.py pilotWrapperScript uses ssl._create_unverified_context to download the second-stage pilot.tar archive without TLS certificate verification and downloads the reference checksum through the same unvalidated channel. An attacker able to redirect or intercept a grid site's network traffic through DNS or routing manipulation can substitute both the executable pilot code and its checksum, causing arbitrary code to run in the pilot context with access to pilot proxy credentials. The fixed implementation validates the server certificate through system trust and X509_CERT_DIR or the grid certificate directory. This issue is fixed in versions 8.0.79, 9.0.22, and 9.1.10.
CVSS 3.1-ontleding
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HHerstel
Er is geen opgeloste versie vastgelegd in de NVD-data. Raadpleeg het leveranciersadvies voor de laatste richtlijnen.
Referenties
- https://github.com/DIRACGrid/DIRAC/commit/68029dfb5ddd8b1e4106851f8e37370aa80ac7ae
- https://github.com/DIRACGrid/DIRAC/commit/92e2e26c63b964b8499bee5e9c2e2821a36eac56
- https://github.com/DIRACGrid/DIRAC/commit/b332c437d064f66ee46f5b45a90a9f7c4bace38d
- https://github.com/DIRACGrid/DIRAC/releases/tag/v8.0.79
- https://github.com/DIRACGrid/DIRAC/releases/tag/v9.0.22
- https://github.com/DIRACGrid/DIRAC/releases/tag/v9.1.10
- https://github.com/DIRACGrid/DIRAC/security/advisories/GHSA-vg99-gr89-qhw9
Gerelateerde CVE's
Recente ernstige kwetsbaarheden met hetzelfde zwakhedentype.
Veelgestelde vragen
Wordt CVE-2026-61668 actief misbruikt?
CVE-2026-61668 staat niet in de CISA KEV-catalogus.
Hoe ernstig is CVE-2026-61668?
CVE-2026-61668 heeft een CVSS 3.1-basisscore van 8.1, beoordeeld als high.
Hoe verhelp ik CVE-2026-61668?
Pas de patch of het advies van de leverancier toe en controleer dat er geen getroffen versies meer op uw apparaten staan.
Hoe Secuno hiermee omgaat
Secuno correleert kwetsbaarheden zoals CVE-2026-61668 dagelijks tegen de werkelijke software-inventaris op elk beheerd apparaat. In plaats van een statische ernst wordt elke match in context gescoord: exploitbeschikbaarheid, EPSS, de blootstelling van het asset en bedrijfskriticiteit bepalen de prioriteit. Als een getroffen versie ergens in uw portfolio aanwezig is, verschijnt die automatisch met een geprioriteerd hersteltraject.
Data uit de NVD, CISA KEV-catalogus en FIRST EPSS. CVSS 3.1-basisscore getoond indien beschikbaar.