CVE-2026-35410
Last modified
CVE-2026-35410 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLoginRedirectAllowed function fails to correctly identify certain malformed URLs as external, allowing attackers to bypass redirect allow-list validation and redirect users to arbitrary external domains upon successful authentication. This vulnerability is fixed in 11.16.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Monospace | Directus | < 11.16.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-35410?
How severe is CVE-2026-35410?
How do I fix CVE-2026-35410?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-35405libp2p-rust is the official rust language Implementation of …7.5
- CVE-2026-35406Aardvark-dns is an authoritative dns server for A/AAAA conta…7.5
- CVE-2026-35407Saleor is an e-commerce platform. From 2.10.0 to before 3.23…6.5
- CVE-2026-35408Directus is a real-time API and App dashboard for managing S…9.3
- CVE-2026-35409Directus is a real-time API and App dashboard for managing S…7.7
- CVE-2026-3541Inappropriate implementation in CSS in Google Chrome prior t…8.8
- CVE-2026-35411Directus is a real-time API and App dashboard for managing S…4.3
- CVE-2026-35412Directus is a real-time API and App dashboard for managing S…8.1
- CVE-2026-35413Directus is a real-time API and App dashboard for managing S…5.3
- CVE-2026-35414OpenSSH before 10.3 mishandles the authorized_keys principal…8.1
- CVE-2026-35415Integer overflow or wraparound in Windows Storage Spaces Con…7.8
- CVE-2026-35416Access of resource using incompatible type ('type confusion'…7
Are you affected by CVE-2026-35410?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
