CVE-2021-26594
Last modified
CVE-2021-26594 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. EPSS estimates a 1.17% chance of exploitation in the next 30 days.
Description
In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rangerstudio | Directus | >= 8.0.0, <= 8.8.1 |
References
- https://github.com/sgranel/directusv8Exploit, Third Party Advisory
- https://github.com/sgranel/directusv8Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-26594?
How severe is CVE-2021-26594?
How do I fix CVE-2021-26594?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-26585A potential vulnerability has been identified in HPE OneView…5.5
- CVE-2021-26586A potential security vulnerability has been identified in th…7.5
- CVE-2021-26587A potential DOM-based Cross Site Scripting security vulnerab…6.5
- CVE-2021-26588A potential security vulnerability has been identified in HP…9.8
- CVE-2021-26589A potential security vulnerability has been identified in HP…6.1
- CVE-2021-26593In Directus 8.x through 8.8.1, an attacker can see all users…7.5
- CVE-2021-26595In Directus 8.x through 8.8.1, an attacker can learn sensiti…5.3
- CVE-2021-26596An issue was discovered in Nokia NetAct 18A. A malicious use…5.4
- CVE-2021-26597An issue was discovered in Nokia NetAct 18A. A remote user, …6.5
- CVE-2021-26598ImpressCMS before 1.4.3 has Incorrect Access Control because…5.3
- CVE-2021-26599ImpressCMS before 1.4.3 allows include/findusers.php groups …9.8
- CVE-2021-26600ImpressCMS before 1.4.3 has plugins/preloads/autologin.php t…9.8
Are you affected by CVE-2021-26594?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
