{"id":"CVE-2026-35411","aliases":["GHSA-q75c-4gmv-mg9x"],"url":"https://o3.security/vulnerability/CVE-2026-35411","summary":"Directus is an Open Redirect in Admin 2FA Setup Page","details":"Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. When an administrator who has not yet configured Two-Factor Authentication (2FA) visits a crafted URL, they are presented with the legitimate Directus 2FA setup page. After completing the setup process, the application redirects the user to the attacker-controlled URL specified in the redirect parameter without any validation. This vulnerability could be used in phishing attacks targeting Directus administrators, as the initial interaction occurs on a trusted domain. This vulnerability is fixed in 11.16.1.","published":"2026-04-06T21:33:06.664Z","modified":"2026-07-27T03:56:27.849660257Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"directus","fixedVersion":"11.16.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35411.json"},{"type":"ADVISORY","url":"https://github.com/directus/directus/security/advisories/GHSA-q75c-4gmv-mg9x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35411"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-27T03:56:27.849660257Z"}}