OVERVIEW CVE-2026-35442 is an information disclosure vulnerability in Directus prior to version 11.17.0 that affects the handling of concealed data fields. The flaw allows aggregate functions (min, max) to bypass data masking controls and return raw, unencrypted values from the database when combined with groupBy operations. This creates a pathway for extracting highly sensitive information such as static API tokens and two-factor authentication secrets from the directus_users table. SEVERITY The vulnerability carries a CVSS v3.1 score of 8.1 (HIGH) with a network-based attack vector requiring low complexity and low privileges. Any authenticated user with basic read access to an affected collection can exploit this flaw without user interaction. The impact is severe, resulting in high confidentiality and integrity compromise through exposure of authentication credentials and secrets, though system availability remains unaffected. EXPLOITATION STATUS This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and shows no evidence of active exploitation in the wild. The EPSS score of 0.0002 indicates a very low probability of exploitation relative to other disclosed CVEs. Community attention remains minimal, with the vulnerability classified as inactive on threat tracking platforms. Organizations should prioritize patching to version 11.17.0 during normal maintenance windows, though the low exploitation probability reduces immediate urgency.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.17.0CPE matchmatch criteria | cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.