PT-2026-7914 · Directus · Directus

Denizparlak

·

Publicado

2026-02-12

·

Atualizado

2026-02-13

·

CVE-2026-26185

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Directus versions prior to 11.14.1
Description A timing-based user enumeration issue exists in the password reset functionality. Providing an invalid reset url parameter results in differing response times – approximately 500ms – between existing and non-existing users, allowing for reliable user enumeration. The password reset endpoint attempts to implement timing protection, but URL validation occurs before this protection is applied, enabling the identification of valid user accounts based on response times. This issue compromises user privacy and could facilitate targeted phishing attacks by confirming account existence.
Recommendations Update to version 11.14.1 or later.

Exploit

Correção

Side Channel Attack

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-26185
GHSA-JR94-GJ3H-C8RF

Produtos afetados

Directus