Junglewise Threat Intelligence

CVE-2026-35442: Directus sensitive information disclosure via aggregate queries

CVE-2026-35442 · Severity: high · CVSS 8.1 · Published 2026-04-06

Technologies: directus (npm). Vendors: Directus, npm.

Executive brief

Directus is a headless CMS and backend platform that protects sensitive fields like API tokens and two-factor authentication secrets by masking them on read. However, aggregate query functions (min/max) bypass this protection and return raw values. An authenticated attacker with basic read access can extract all API tokens and 2FA seeds, enabling account takeover of any user including administrators without requiring their credentials.

Technical details

This vulnerability affects Directus field masking logic for concealed field types. Fields marked with the conceal special type are protected by payload processing that replaces real values with masked placeholders during standard read operations. However, aggregate query results use a different nested structure—operations are keyed under their function name (min/max) rather than appearing as flat field keys. The masking logic does not account for this nested format and silently skips concealed fields in aggregate responses, returning raw database values including static API tokens and TOTP seeds from directus_users. Exploitation requires authentication and read access to the affected collection. An attacker can use groupBy combined with aggregate functions to harvest all concealed field values. The vulnerability was patched in version 11.17.0.

Affected products

  • Directus Directus <11.17.0

Timeline

  • 2026-04-04: disclosed: Vulnerability published by Directus security team
  • 2026-04-04: patched: Fixed in version 11.17.0

References

Related threats