Exposure of Sensitive Data in Directus API Management Platform
CVE-2026-39943

6.5MEDIUM

Key Information:

Vendor

Directus

Status
Vendor
CVE Published:
9 April 2026

What is CVE-2026-39943?

Directus, an API and app dashboard for managing SQL databases, has a vulnerability that allows sensitive information, including user tokens, two-factor authentication secrets, and API keys, to be stored in plaintext. This happens because the sanitization process in the revision snapshot code is not consistently applied. It is crucial for users to upgrade to version 11.17.0 or later to mitigate the risk of potential data exposure from revision records.

Affected Version(s)

directus < 11.17.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.