CVE-2026-35408Disclosure(monospace / directus)

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch monospace directus systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-Opener-Policy (COOP) HTTP response header. Without this header, a malicious cross-origin window that opens the Directus login page retains the ability to access and manipulate the window object of that page. An attacker can exploit this to intercept and redirect the OAuth authorization flow to an attacker-controlled OAuth client, causing the victim to unknowingly grant access to their authentication provider account (e.g. Google, Discord). This vulnerability is fixed in 11.17.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • directus

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-06); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
directus

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-06: 3Mentions · 2026-04-07: 1Patch / Workaround · 2026-04-06: 2Technical Details · 2026-04-06: 3Technical Details · 2026-04-07: 104-0604-07
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-063
Disclosure2Patch1
2026-04-071
Disclosure1
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35408 Cross-Origin-Opener-Policy Header Missing in Directus SSO Login Pages Be... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35408 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The entry announces CVE-2026-35408, noting a missing Cross-Origin-Opener-Policy header on Directus SSO login pages, but provides no PoC, exploit, or patch information.

    0000036
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-35408: HIGH] Cyber security alert: Vulnerability in Directus's SSO login pages prior to version 11.17.0 allowed for possible OAuth authorization flow interception, now fixed in the latest release.#cve,CVE-2026-35408,#cybersecurity https://cvefind.com/CVE-2026-35408

    Post summary

    The alert identifies CVE-2026-35408 as an OAuth flow interception flaw in Directus SSO login pages and confirms the issue has been fixed in the latest release.

    0000058
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35408 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-O… https://www.cve.org/CVERecord?id=CVE-2026-35408 ----- Traducción: CVE-2026-35408 Dir… http://infoflow.cloud`

    Post summary

    The post cites CVE‑2026‑35408, noting that Directus SSO login pages lacked a Cross‑Origin header; no PoC, exploit, patch, or active exploitation details are disclosed.

    0000033
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35408 Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus's Single Sign-On (SSO) login pages lacked a Cross-Origin-O… https://www.cve.org/CVERecord?id=CVE-2026-35408

    Post summary

    The snippet reports a CVE affecting Directus SSO login pages due to a missing cross‑origin policy before version 11.17.0, highlighting the vulnerability and a version update that presumably addresses it.

    00000185
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmonospacedirectus-node.js-

Explore more