Junglewise Threat Intelligence

CVE-2026-26185: Directus user enumeration via password reset timing attack

CVE-2026-26185 · Severity: low · CVSS 3.1 · Published 2026-02-12

Technologies: directus (npm), @directus/api (npm). Vendors: Directus, npm.

Executive brief

Directus is a popular open-source headless CMS and API platform. A timing-based vulnerability in its password reset functionality allows attackers to enumerate valid user accounts by measuring response delays, potentially enabling targeted phishing campaigns and account enumeration attacks.

Technical details

The vulnerability is a timing-based user enumeration (CWE-203) in the password reset endpoint. The password reset mechanism includes timing protection to prevent enumeration; however, URL parameter validation executes before this protection is applied. When an attacker provides an invalid reset_url parameter, the response time differs by approximately 500ms between existing and non-existing users, reliably revealing account existence. No authentication is required; exploitation requires only network access to the password reset endpoint. The vulnerability affects Directus versions up to 11.15.0 and @directus/api versions prior to 32.2.0, with fixes available in 11.15.0 and 32.2.0 respectively.

Affected products

  • Directus Directus ≤ 11.15.0
  • Directus @directus/api < 32.2.0

Timeline

  • 2026-02-12: disclosed: Advisory GHSA-jr94-gj3h-c8rf published
  • 2026-02-12: patched: Fixes available in Directus 11.15.0 and @directus/api 32.2.0

References

Related threats