SQL Injection Vulnerability in Directus PostgreSQL Implementation
CVE-2026-10716

7.5HIGH

Key Information:

Vendor

Directus

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-10716?

Directus is vulnerable to an authenticated SQL injection flaw during the collection creation process when utilizing PostgreSQL with PostGIS enabled. Administrators can inadvertently introduce risk by creating a geometry field where the type starts with 'geometry' but contains SQL syntax controlled by an attacker, enabling potential database access and manipulation. This issue impacts versions of Directus before 12.1.0, requiring prompt updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Directus Windows 0 < 12.1.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Santiago Alvarez
Oscar Naveda
.