Improper Authentication in Directus - #VU144561

 

Improper Authentication in Directus - #VU144561

Published: August 21, 2026


Vulnerability identifier: #VU144561
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute manual trigger flows intended only for authenticated users.

The vulnerability exists due to improper authentication in the manual trigger handler and public trigger endpoint when handling unauthenticated requests to POST /flows/trigger/:id. A remote attacker can send a crafted request to execute manual trigger flows intended only for authenticated users.

Exploitation requires an active manual Flow, the Flow to be enabled for a collection readable by the Public role, knowledge of the Flow ID, and, if item selection is required, knowledge of a readable item ID.


Affected software

Directus

Remediation

Install security update from vendor's website.

Directus - update to 12.2.0

External References

Related Security Bulletins