PT-2026-30325 · Directus · Directus

Published

2026-04-04

·

Updated

2026-04-06

·

CVE-2026-35408

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Directus versions prior to 11.17.0
Description Directus SSO login pages were missing the Cross-Origin-Opener-Policy (COOP) HTTP response header. This allowed a malicious cross-origin window to access and manipulate the window object of the Directus login page. An attacker could intercept and redirect the OAuth authorization flow to a malicious OAuth client, potentially gaining access to the victim's authentication provider account (e.g., Google, Discord). A successful attack could lead to unauthorized access to the victim's linked identity provider account or account takeover of the Directus instance.
Recommendations Upgrade to Directus version 11.17.0 or later. As a workaround, configure your reverse proxy or web server to add the Cross-Origin-Opener-Policy: same-origin HTTP response header to all Directus responses.

Fix

Protection Mechanism Failure

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35408
GHSA-8M32-P958-JG99

Affected Products

Directus