CVE-2026-29080: Rucio SQL Injection in FilterEngine Oracle JSON Path via DID Search API
Summary
A SQL injection vulnerability in the Oracle path of FilterEngine.createsqlaquery allows any authenticated Rucio user to execute arbitrary SQL against the backend database through the DID search endpoint (GET /dids/<scope>/dids/search). Attacker-controlled filter keys and values are interpolated directly into sqlalchemy.text via Python str.format, completely bypassing parameterization. This enables full database compromise including extraction of authentication tokens, password hashes, and all managed data identifiers. The vulnerability is affecting deployments using the default metadata plugin configuration jsonmeta with Oracle database backends.
Details
Will follow in two weeks (2025-05-19).
Impact
Vulnerability type: SQL Injection (CWE-89)
Who is impacted:
- All Oracle-based Rucio deployments using the default metadata plugin configuration (jsonmeta). - Not affected are PostgreSQL/MySQL deployments using the default jsonmeta plugin (SQLAlchemy parameterizes the JSON path operations via bind parameters on non-Oracle dialects).
What an attacker can do:
- Full database read access: Extract any table including identities (password hashes and salts), tokens (active authentication sessions), accounts (user enumeration), rsesettings (storage endpoint credentials), and rules (data management policies). - Password hash extraction: Combined with Rucio's use of single-iteration SHA-256 for password hashing (no KDF), extracted hashes can be cracked at GPU speed. - Authentication token theft: Active bearer tokens can be extracted and used for immediate session hijacking. - Data modification: Oracle PL/SQL enables INSERT/UPDATE/DELETE operations via DML within subqueries and PL/SQL blocks. - Potential remote code execution: Via Oracle's UTLHTTP, DBMSSCHEDULER, or Java stored procedures if the database user has elevated privileges.
Required attacker privileges: Any authenticated Rucio user. Authentication tokens can be obtained via any supported method (userpass, x509, OIDC, SAML, SSH, GSS). No special roles or administrative permissions are required. The GET /dids/<scope>/dids/search endpoint is available to all authenticated users.
Other sources
A SQL injection vulnerability in FilterEngine.createsqlaquery() allows any authenticated Rucio user to execute arbitrary SQL against the backend database through the DID search endpoint (GET /dids/<scope>/dids/search). On Oracle deployments attacker-controlled filter keys and values are interpolated directly into sqlalchemy.text() via Python .format(), completely bypassing parameterization. This enables full database compromise including extraction of authentication tokens, password hashes, and all managed data identifiers. This affects versions 1.27.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1.
The vulnerability exists in lib/rucio/core/didmetaplugins/filterengine.py within the createsqlaquery() method. When the database dialect is Oracle, filter expressions for JSON metadata columns are constructed using text() with Python string formatting. Both key and value are attacker-controlled strings derived from HTTP query parameters. The text() function creates a raw SQL fragment — it does not escape or parameterize its contents.
Any authenticated Rucio user can exploit this through the DID search API to execute arbitrary SQL against the backend database. This can expose all managed data identifiers and sensitive tables such as identities, tokens, accounts, rsesettings, and rules, and may allow modification of database contents. The issue affects Oracle deployments using the default jsonmeta plugin and does not affect PostgreSQL or MySQL deployments using that plugin.
This vulnerability has been fixed in versions 35.8.5, 38.5.5, 39.4.2, and 40.1.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-29080?
CVE-2026-29080 is classified as a moderate severity SQL injection vulnerability.
How do I fix CVE-2026-29080?
To mitigate CVE-2026-29080, upgrade Rucio to version 40.1.1, 39.4.2, or 38.5.5 depending on your currently installed version.
Who is affected by CVE-2026-29080?
Any authenticated user of Rucio versions before the patched versions is potentially affected by CVE-2026-29080.
What kind of attack can be performed using CVE-2026-29080?
An attacker can execute arbitrary SQL queries against the database through the DID search API endpoint.
When was CVE-2026-29080 disclosed?
CVE-2026-29080 was disclosed in 2026, highlighting risks related to SQL injection in the Rucio platform.