CVE-2022-26969 is a critical vulnerability affecting Directus versions prior to 9.7.0, stemming from insecure default Cross-Origin Resource Sharing (CORS) settings. With a CVSS score of 9.8, it presents a severe risk, allowing unauthenticated attackers to achieve full compromise (confidentiality, integrity, and availability) over the network with low attack complexity. Despite its high severity and FAUCET Risk Score of 80/100, there is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.7.0CPE matchmatch criteria | cpe:2.3:a:monospace:directus:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.