
CVE-2026-35409 Server-Side Request Forgery Protection Bypass in Directus Prior to 11.16.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35409
Post summary
CVE‑2026‑35409 is a Server‑Side Request Forgery bypass discovered in Directus versions older than 11.16.0, with the fix available in 11.16.0 or later. No PoC, exploit code, or active exploitation has been reported.

