Vendor
Directus Authorization Bypass via Cache Key Collision (CVE-2026-61836)
1 CVEA vulnerability in Directus allows for an authorization bypass when response caching is enabled, leading to cross-share confidentiality breaches where sensitive data scoped for one share can be accessed by another share token holder or anonymous users due to an unsegmented cache key.
Directus SSRF Vulnerability via IPv4-Mapped IPv6 Addresses
2 rules 1 TTP 3 IOCsDirectus versions before 11.16.0 are vulnerable to Server-Side Request Forgery (SSRF) due to a bypass in IP address validation using IPv4-Mapped IPv6 addresses, allowing attackers to access internal services and sensitive cloud metadata.
Directus File Overwrite Vulnerability (CVE-2026-39942)
2 rules 2 TTPs 1 CVEA file overwrite vulnerability (CVE-2026-39942) exists in Directus versions prior to 11.17.0, where an attacker can overwrite another user's files by manipulating the filename_disk parameter in the PATCH /files/{id} endpoint, potentially leading to data corruption or privilege escalation.