Exposure of Sensitive Data in Directus API Management Platform
CVE-2026-39943
6.5MEDIUM
What is CVE-2026-39943?
Directus, an API and app dashboard for managing SQL databases, has a vulnerability that allows sensitive information, including user tokens, two-factor authentication secrets, and API keys, to be stored in plaintext. This happens because the sanitization process in the revision snapshot code is not consistently applied. It is crucial for users to upgrade to version 11.17.0 or later to mitigate the risk of potential data exposure from revision records.
Affected Version(s)
directus < 11.17.0
