CVE-2021-26594: High severity directus 7 api vulnerability
UNSUPPORTED WHEN ASSIGNED In Directus 8.x through 8.8.1, an attacker can switch to the administrator role (via the PATCH method) without any control by the back end. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26594?
CVE-2021-26594 is classified as a critical vulnerability due to the ability of an attacker to assume the administrator role without authorization.
How do I fix CVE-2021-26594?
To mitigate CVE-2021-26594, it is recommended to upgrade to a supported version of Directus, as versions 8.x through 8.8.1 are no longer maintained.
Who is affected by CVE-2021-26594?
CVE-2021-26594 affects users of Directus versions 8.0.0 to 8.8.1 that are no longer supported by the maintainer.
What can an attacker do with CVE-2021-26594?
An attacker exploiting CVE-2021-26594 can change their role to an administrator, gaining full control over the Directus application.
Is there a workaround for CVE-2021-26594?
No official workaround exists for CVE-2021-26594, and the only solution is to upgrade to a supported version of Directus.