CVE-2026-35409: Directus Missing Oauth Validation

A request authorization check verifies primary user, role, or administrative presence but fails to subsequently inspect and validate OAuth constraints (such as scope, audience, or origin/transport) when an OAuth token is present. This allows users or tokens with inappropriate scopes or mismatched audiences to bypass intended logical barriers. OAuth propertie

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-35409-directus-missing-oauth-validation --engine opengrep

Description

A request authorization check verifies primary user, role, or administrative presence but fails to subsequently inspect and validate OAuth constraints (such as scope, audience, or origin/transport) when an OAuth token is present. This allows users or tokens with inappropriate scopes or mismatched audiences to bypass intended logical barriers. OAuth propertie