Directus fixed two high-severity vulnerabilities in versions prior to 11.17.0 that allowed authenticated, low-privilege users to bypass intended protections. One flaw, tracked as CVE-2026-35442, let users extract raw values from fields marked as concealed by abusing aggregate functions such as min and max, especially when combined with groupBy. The exposure could reveal sensitive data stored in affected collections, including static API tokens and two-factor authentication secrets from directus_users.
A second flaw, CVE-2026-39942, affected the file management API and allowed path traversal and broken access control through the PATCH /files/{id} endpoint. By supplying a user-controlled filename_disk value, an authenticated attacker could point writes at another user's storage path, overwrite file contents, and modify metadata such as uploaded_by to obscure the tampering. The issues were classified under weaknesses including CWE-200, CWE-863, CWE-284, and CWE-639, and both were remediated in Directus 11.17.0.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-09, GitHub published the security advisory and release reference for CVE-2026-39942. The vulnerability let a low-privileged authenticated attacker abuse the PATCH /files/{id} endpoint to overwrite another user's file by controlling the filename_disk parameter.
Directus released version 11.17.0 to fix CVE-2026-35442, which exposed concealed field values via aggregate queries, and CVE-2026-39942, which allowed path traversal and broken access control in the file management API. Both issues affected versions prior to 11.17.0.
A vulnerability later tracked as CVE-2026-35442 was received by GitHub's security advisories channel on 2026-04-06. The flaw allowed authenticated users to extract concealed field values through aggregate queries with groupBy in Directus versions before 11.17.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.