LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-35442

CVE-2026-35442 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: April 6, 2026

Directus - Broken Access Control

Published: April 6, 2026Updated: April 6, 2026Remote Exploitable

Overview

Directus < 11.17.0 contains an information disclosure vulnerability caused by incorrect handling of aggregate functions on concealed fields, letting authenticated users with read access extract sensitive concealed data, exploit requires user authentication.

Severity & Score

Severity: High
CVSS Score: 8.1

Impact

Authenticated users can extract sensitive concealed data including API tokens and 2FA secrets, risking account compromise and data leakage.

Mitigation

Update to version 11.17.0 or later.

Details

CVE ID
CVE-2026-35442
Severity
High
CVSS Score
8.1
Type
broken_access_control
Status
new

CWE

  • CWE-200

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N