Improper access control in Directus - CVE-2025-64748
Published: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in concealed fields of the directus_users collection when processing search operations. A remote user can search concealed sensitive fields to disclose sensitive information.
Matching records are returned with masked values, allowing confirmation that searched values such as tokens, TFA secrets, and password hashes exist.