Incorrect authorization in Directus - CVE-2025-64746
Published: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and modify data.
The vulnerability exists due to incorrect authorization in field-level permissions handling when creating a new field with the same name as a previously deleted field. A remote user can create a field with a reused name to disclose sensitive information and modify data.
User interaction is required for exploitation.