Incorrect authorization in Directus - CVE-2026-35442
Published: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information and compromise accounts.
The vulnerability exists due to incorrect authorization in aggregate query handling for concealed fields when processing aggregate queries with groupBy. A remote user can send a crafted aggregate query to disclose sensitive information and compromise accounts.
The issue affects fields with the conceal special type and can expose static API tokens and TOTP secrets from directus_users.