OVERVIEW CVE-2026-35408 is a critical vulnerability in Directus versions prior to 11.17.0 that affects the Single Sign-On (SSO) login pages. The vulnerability stems from the absence of a Cross-Origin-Opener-Policy (COOP) HTTP response header, which allows malicious cross-origin windows to retain access to and manipulate the window object of the Directus login page. SEVERITY The vulnerability carries a CVSS 3.1 score of 9.3 (CRITICAL) with a network-based attack vector, low attack complexity, and no privileges required. The vulnerability exploits user interaction (UI-dependent), and its impact extends across security boundaries, with high confidentiality and integrity impacts. An attacker can intercept and redirect the OAuth authorization flow to an attacker-controlled OAuth client, potentially causing victims to unknowingly grant access to their authentication provider accounts such as Google or Discord. EXPLOITATION STATUS There is no current evidence of active exploitation, as the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog and shows an Inactive Hot List status. The EPSS score of 0.000080 indicates minimal observed exploitation activity in the wild. However, the critical CVSS rating warrants immediate patching, and organizations should upgrade to Directus version 11.17.0 or later to remediate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.17.0CPE matchmatch criteria | cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.