Directus disclosed CVE-2026-61836, a high-severity information disclosure flaw affecting versions prior to 12.0.0 when response caching is enabled. The vulnerability stems from cache keys that included the version, path, query, and accountability.user but failed to incorporate authorization context such as share, role, roles, admin, app, and policies. Because share-token requests and anonymous requests can both resolve to user null, different clients requesting the same URL could receive a cached response generated under another permission context, potentially exposing sensitive data without re-evaluating access controls.
The issue is rated CVSS 8.6 with vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N and is mapped to CWE-524 and CWE-639. A Directus code change addressed the problem by adding the share identifier from req.accountability.share to the cache key namespace, preventing collisions between different share tokens, anonymous requests, and authenticated sessions. The patch also introduced tests confirming that separate share tokens now generate distinct cache keys while repeated anonymous requests and repeated use of the same share token remain consistently cached.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-61836 was published as a high-severity vulnerability affecting Directus versions prior to 12.0.0 when response caching is enabled. The disclosure states that cache-key derivation omitted authorization context, which could cause unauthorized disclosure of sensitive cached data, and notes the issue was fixed in version 12.0.0.
A Directus code change updated API cache key generation to include the share identifier, preventing requests made with different share tokens from colliding with each other, anonymous requests, or authenticated user requests. The commit also added tests validating distinct cache keys for different shares on the same URL.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.