Observable discrepancy in Directus - CVE-2026-26185

 

Observable discrepancy in Directus - CVE-2026-26185

Published: April 23, 2026


Vulnerability identifier: #VU127123
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-26185
CWE-ID: CWE-203
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information about the existence of user accounts.

The vulnerability exists due to an observable discrepancy in the password reset endpoint when handling password reset requests with an invalid reset_url parameter. A remote attacker can send crafted password reset requests and measure response times to disclose sensitive information about the existence of user accounts.

The response time differs by approximately 500ms between existing and non-existing users.


Affected software

Directus

How to mitigate CVE-2026-26185

Install security update from vendor's website.

Directus - update to 11.15.0

External References

Related Security Bulletins