Junglewise Threat Intelligence

CVE-2026-35412: Directus authorization bypass in TUS resumable upload endpoint

CVE-2026-35412 · Severity: high · CVSS 7.1 · Published 2026-04-06

Technologies: directus (npm). Vendors: Directus, npm.

Executive brief

Directus is an open-source data platform used to manage SQL database content and digital assets. A security flaw in its resumable upload feature allows any logged-in user with basic upload permissions to overwrite any file in the system, even those belonging to other users or administrators. This could lead to permanent data loss, corruption of important application assets, and unauthorized modification of sensitive files.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the Directus TUS resumable upload endpoint (/files/tus). While the standard REST upload path correctly enforces item-level permissions, the TUS controller only performs collection-level checks on the 'directus_files' table. This allows an authenticated attacker with basic upload privileges to provide a specific file UUID and overwrite the target file's content and metadata, bypassing row-level security rules (e.g., 'owner-only' restrictions). The vulnerability results in the deletion of the original file from storage and its replacement with attacker-controlled data. This is resolved in version 11.16.1; a temporary workaround is to set TUS_ENABLED=false.

Affected products

  • Directus Directus < 11.16.1

Timeline

  • 2026-04-02: advisory: GitHub Security Advisory published
  • 2026-04-06: disclosed: CVE published to NVD
  • 2026-04-06: patched: Fix released in version 11.16.1

References

Related threats