{"id":"CVE-2026-26185","aliases":["GHSA-jr94-gj3h-c8rf"],"url":"https://o3.security/vulnerability/CVE-2026-26185","summary":"Directus Affected by User Enumeration via Password Reset Timing Attack","details":"### Summary\n\nA timing-based user enumeration vulnerability exists in the password reset functionality. When an invalid reset_url parameter is provided, the response time differs by approximately 500ms between existing and non-existing users, enabling reliable user enumeration.\n\n### Details\n\nThe password reset endpoint implements a timing protection mechanism to prevent user enumeration; however, URL validation executes before the timing protection is applied. This allows an attacker to distinguish between valid and invalid user accounts based on response timing differences.\n\n### Impact\n\nThis vulnerability violates user privacy and may facilitate targeted phishing attacks by allowing attackers to confirm the existence of user accounts.","published":"2026-02-12T21:54:13.901Z","modified":"2026-08-12T03:51:44.736488990Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"directus","fixedVersion":"11.14.1"},{"ecosystem":"npm","name":"@directus/api","fixedVersion":"32.2.0"}],"fix":{"url":"https://github.com/directus/directus/commit/e69aa7a5248c6e3e822cb1ac354dee295df90b2a","label":"directus/directus@e69aa7a"},"references":[{"type":"WEB","url":"https://github.com/directus/directus/releases/tag/v11.14.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26185.json"},{"type":"ADVISORY","url":"https://github.com/directus/directus/security/advisories/GHSA-jr94-gj3h-c8rf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26185"},{"type":"FIX","url":"https://github.com/directus/directus/commit/e69aa7a5248c6e3e822cb1ac354dee295df90b2a"},{"type":"FIX","url":"https://github.com/directus/directus/pull/26485"},{"type":"PACKAGE","url":"https://github.com/directus/directus"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.736488990Z"}}