Incorrect behavior order in Directus - #VU141289
Published: August 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify attribution metadata.
The vulnerability exists due to incorrect behavior order in UsersService.deleteMany when handling a delete request for a user. A remote attacker can send a specially crafted request targeting a user they cannot delete to modify attribution metadata.
The issue can nullify authorship and sender fields in comments, notifications, and content version records.