NONE · 0

CVE-2026-10716

Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a g...

Vulnerability Description

Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-10716?

CVE-2026-10716 is a documented vulnerability. Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a g...

How severe is CVE-2026-10716?

CVSS scoring is not yet available for CVE-2026-10716. Check NVD for updates.

Is there a patch for CVE-2026-10716?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.