Description

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus' TUS resumable upload endpoint (/files/tus) allows any authenticated user with basic file upload permissions to overwrite arbitrary existing files by UUID. The TUS controller performs only collection-level authorization checks, verifying the user has some permission on directus_files, but never validates item-level access to the specific file being replaced. As a result, row-level permission rules (e.g., "users can only update their own files") are completely bypassed via the TUS path while being correctly enforced on the standard REST upload path. This vulnerability is fixed in 11.16.1.

INFO

Published Date :

2026-04-06T21:33:44.867Z

Last Modified :

2026-04-07T16:23:16.091Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-35412 vulnerability.

Vendors Products
Directus
  • Directus
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-35412.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact