PT-2026-30328 · Directus · Directus
Akokonunes
+2
·
Published
2026-04-04
·
Updated
2026-04-06
·
CVE-2026-35411
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Directus versions prior to 11.16.1
Description
Directus is susceptible to an open redirect issue through the
redirect parameter on the /admin/tfa-setup page. An administrator who has not configured Two-Factor Authentication (2FA) may be redirected to an attacker-controlled URL after completing the 2FA setup process, as the application lacks validation of the redirect destination. This could be leveraged in phishing attacks targeting Directus administrators.Recommendations
Update to version 11.16.1 or later.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Directus