Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, when response caching is enabled, the cache-key derivation in api/src/utils/get-cache-key.ts includes version, path, query, and accountability.user but omits authorization context such as share, role, roles, admin, app, and policies. Directus share tokens and anonymous requests can both reduce to user null, so different shares or anonymous clients requesting the same URL and query can receive a permission-filtered cached response without permission re-evaluation. This issue is fixed in version 12.0.0.
CVE-2026-61836
This high-severity CVE scores 8.6 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.3%, top 80% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.6
- EG Score
- 8.6(medium)
- EPSS
- 19.8%
- KEV
- Not listed
Published
July 15, 2026
Last Modified
July 15, 2026
Advisory Details (4)
Auto-updated Jul 15, 2026Authorization-dependent response served from unsegmented cache key · Advisory · directus/directus · GitHub
https://github.com/directus/directus/security/advisories/GHSA-c6w9-5g5j-jh2pv12.0.0
Patch available: directus/directus v12.0.0
https://github.com/directus/directus/releases/tag/v12.0.0Add share to cache key
Fix merged in directus/directus PR #27707 on 2026-06-10 — awaiting tagged release
https://github.com/directus/directus/pull/27707commit 7ba4efb97525 (directus/directus)
Fix landed in directus/directus commit 7ba4efb97525 — awaiting tagged release
https://github.com/directus/directus/commit/7ba4efb97525d3af33570537c76e44baea767f13Vendor Advisories for CVE-2026-61836(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Affected Packages
(1 across 1 ecosystem)
npm(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| directus | — | 12.0.0 | — |
Weakness Classification(2)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 9× in last 7d / 11× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-22 14:08 UTCEPSS rescore
- 2026-07-21 15:25 UTCEPSS rescore
- 2026-07-21 15:25 UTCEPSS rescore
- 2026-07-20 17:08 UTCEPSS rescore
- 2026-07-19 14:31 UTCEPSS rescore
- 2026-07-19 02:29 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-16 17:03 UTCEPSS rescore
- 2026-07-15 14:51 UTCEG score recompute
- 2026-07-15 14:49 UTCMITRE cvelistV5first tracked
Frequently asked(5)
What is CVE-2026-61836?
When was CVE-2026-61836 disclosed?
Is CVE-2026-61836 actively exploited?
What is the CVSS score of CVE-2026-61836?
How do I remediate CVE-2026-61836?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-61836
Is Your Infrastructure Affected by CVE-2026-61836?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.