Open Redirect in Directus API Dashboard
CVE-2026-35411
4.3MEDIUM
What is CVE-2026-35411?
Directus, a real-time API and application dashboard for SQL database content management, has a vulnerability related to open redirection. Administrators who have not yet configured Two-Factor Authentication (2FA) may be tricked into visiting a malicious URL. This occurs when they interact with a specially crafted redirect link on the /admin/tfa-setup page. After completing the legitimate 2FA setup process, the application improperly redirects the user to an attacker-controlled site specified in the redirect parameter, thereby bypassing any validation. This weakness poses a significant risk, making it exploitable for phishing attempts against Directus administrators.
Affected Version(s)
directus < 11.16.1
