Improper access control in Directus - CVE-2025-64748
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in concealed fields of the directus_users collection when processing search operations. A remote user can search concealed sensitive fields to disclose sensitive information.
Matching records are returned with masked values, allowing confirmation that searched values such as tokens, TFA secrets, and password hashes exist.