CVE-2026-39942: Directus has a Path Traversal and Broken Access Control in File Management API
Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, the PATCH /files/{id} endpoint accepts a user-controlled filenamedisk parameter. By setting this value to match the storage path of another user's file, an attacker can overwrite that file's content while manipulating metadata fields such as uploadedby to obscure the tampering. This vulnerability is fixed in 11.17.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39942?
CVE-2026-39942 is classified as a critical vulnerability due to its potential for arbitrary file access and exploitation.
How do I fix CVE-2026-39942?
To mitigate CVE-2026-39942, upgrade Directus to version 11.17.0 or later.
What is affected by CVE-2026-39942?
CVE-2026-39942 affects all versions of Directus prior to 11.17.0.
What are the implications of CVE-2026-39942 for users?
Users may experience unauthorized access to files, leading to data leakage or alteration.
Is there a workaround for CVE-2026-39942 if I cannot upgrade?
No official workarounds have been provided for CVE-2026-39942; upgrading is strongly recommended.