CVE-2026-73975
Received Received - Intake

Authenticated SPARQL Injection in djehuty Repository System

Vulnerability report for CVE-2026-73975, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

djehuty is a research data repository system developed by 4TU.ResearchData. Prior to version 26.3.2, an authenticated depositor can inject arbitrary SPARQL into a state-modifying (DELETE/INSERT) query by supplying a crafted session name, letting them write (and delete) arbitrary triples anywhere in the RDF store. Because the RDF store is shared across all accounts and datasets, this is an integrity compromise of the whole repository's metadata, not just the attacker's own records. Having a logged-in account is a precondition. djehuty allows self-registration via ORCID/SAML, so this is a low barrier in typical deployments. This issue has been patched in version 26.3.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
4tu_researchdata djehuty to 26.3.2 (exc)
4tu_researchdata djehuty 26.3.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-943 The product generates a query intended to access or manipulate data in a data store such as a database, but it does not neutralize or incorrectly neutralizes special elements that can modify the intended logic of the query.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authenticated SPARQL injection vulnerability in the djehuty research data repository system. An attacker with a valid account can inject malicious SPARQL queries by crafting a session name with a double-quote character. This bypasses input validation and allows writing or deleting arbitrary RDF triples in the shared repository metadata, compromising the integrity of the entire system.

Detection Guidance

To detect this vulnerability, check if your djehuty instance is running a version prior to 26.3.2. Review server logs for suspicious SPARQL query patterns or unauthorized modifications to RDF triples. Look for session names containing special characters like double quotes in the session editing endpoint logs.

Impact Analysis

An attacker could modify or delete metadata across all datasets in the repository, not just their own. This could lead to data corruption, loss of research records, or misrepresentation of stored information. The attack requires only low-privilege access, as self-registration is often allowed via ORCID or SAML.

Compliance Impact

This vulnerability could lead to non-compliance with data integrity requirements in GDPR and HIPAA. Unauthorized modifications to metadata could violate record-keeping obligations, data accuracy principles, and audit trail integrity, potentially resulting in regulatory penalties or loss of certification.

Mitigation Strategies

Immediately upgrade djehuty to version 26.3.2 or later. If upgrading is not possible, restrict access to the session editing endpoint (PUT /my/sessions/<uuid>/edit) and review all user accounts for unauthorized changes. Monitor RDF store integrity for unexpected triple modifications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73975. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart