CVE-2026-26185

MEDIUM

NPM Directus < 11.14.1 - Information Disclosure

Title source: rule
STIX 2.1

Description

Directus is a real-time API and App dashboard for managing SQL database content. Before 11.14.1, a timing-based user enumeration vulnerability exists in the password reset functionality. When an invalid reset_url parameter is provided, the response time differs by approximately 500ms between existing and non-existing users, enabling reliable user enumeration. This vulnerability is fixed in 11.14.1.

Scores

CVSS v3 5.3
EPSS 0.0001
EPSS Percentile 2.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-203
Status published
Products (3)
directus/api 0 - 32.2.0npm
monospace/directus < 11.15.0
npm/directus 0 - 11.14.1npm
Published Feb 12, 2026
Tracked Since Feb 18, 2026