CVE-2026-26185

Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration vulnerability exists in the password reset functionality. When an invalid reset_url parameter is provided, the response time differs by approximately 500ms between existing and non-existing users, enabling reliable user enumeration. This vulnerability is fixed in 11.14.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*

History

20 Feb 2026, 21:09

Type Values Removed Values Added
CPE cpe:2.3:a:monospace:directus:*:*:*:*:*:node.js:*:*
First Time Monospace
Monospace directus
Summary
  • (es) Directus es una API en tiempo real y un panel de control de aplicaciones para gestionar contenido de bases de datos SQL. Antes de 11.14.1, existe una vulnerabilidad de enumeración de usuarios basada en tiempo en la funcionalidad de restablecimiento de contraseña. Cuando se proporciona un parámetro reset_url no válido, el tiempo de respuesta difiere en aproximadamente 500 ms entre usuarios existentes y no existentes, lo que permite una enumeración de usuarios fiable. Esta vulnerabilidad se ha corregido en 11.14.1.
References () https://github.com/directus/directus/commit/e69aa7a5248c6e3e822cb1ac354dee295df90b2a - () https://github.com/directus/directus/commit/e69aa7a5248c6e3e822cb1ac354dee295df90b2a - Patch
References () https://github.com/directus/directus/pull/26485 - () https://github.com/directus/directus/pull/26485 - Issue Tracking
References () https://github.com/directus/directus/releases/tag/v11.14.1 - () https://github.com/directus/directus/releases/tag/v11.14.1 - Product, Release Notes
References () https://github.com/directus/directus/security/advisories/GHSA-jr94-gj3h-c8rf - () https://github.com/directus/directus/security/advisories/GHSA-jr94-gj3h-c8rf - Vendor Advisory

12 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 22:16

Updated : 2026-02-20 21:09


NVD link : CVE-2026-26185

Mitre link : CVE-2026-26185

CVE.ORG link : CVE-2026-26185


JSON object : View

Products Affected

monospace

  • directus
CWE
CWE-203

Observable Discrepancy