Cleartext storage of sensitive information in Directus - CVE-2026-39943
Published: April 23, 2026
Directus
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to cleartext storage of sensitive information in revision history records in directus_revisions when creating or updating items or auto-suspending users after failed login attempts. A remote user can read revision records or flow logs to disclose sensitive information.
Exposed data may include tokens, two-factor authentication secrets, external authentication identifiers, stored credentials, authentication data, and AI provider API keys.