Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35408

34
FAUCET Score

OVERVIEW CVE-2026-35408 is a critical vulnerability in Directus versions prior to 11.17.0 that affects the Single Sign-On (SSO) login pages. The vulnerability stems from the absence of a Cross-Origin-Opener-Policy (COOP) HTTP response header, which allows malicious cross-origin windows to retain access to and manipulate the window object of the Directus login page. SEVERITY The vulnerability carries a CVSS 3.1 score of 9.3 (CRITICAL) with a network-based attack vector, low attack complexity, and no privileges required. The vulnerability exploits user interaction (UI-dependent), and its impact extends across security boundaries, with high confidentiality and integrity impacts. An attacker can intercept and redirect the OAuth authorization flow to an attacker-controlled OAuth client, potentially causing victims to unknowingly grant access to their authentication provider accounts such as Google or Discord. EXPLOITATION STATUS There is no current evidence of active exploitation, as the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and shows an Inactive Hot List status. The EPSS score of 0.000080 indicates minimal observed exploitation activity in the wild. However, the critical CVSS rating warrants immediate patching, and organizations should upgrade to Directus version 11.17.0 or later to remediate this risk.

Impacted Technologies

VendorProductVersion(s)CPE
< 11.17.0CPE matchmatch criteria
cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

8.7HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 2nd percentile among its peer group of 834 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

npmpatch availablevia ghsa
Product: directusFixed in: 11.17.0
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

npmGHSA-8m32-p958-jg99high

Directus: Missing Cross-Origin Opener Policy

Apr 4, 2026

References

github.com / directus/directus/security/advisories/GHSA-8m32-p958-jg99
Vendor Advisory