CVE-2026-10716: Directus <12.1.0 - Authenticated time-based SQL injection in PostgreSQL/PostGIS collection creation
Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Directusto a version that resolves this vulnerability.Fixed in 12.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10716?
CVE-2026-10716 has a risk score of 44 indicating a medium severity level.
What is CVE-2026-10716?
CVE-2026-10716 is an authenticated SQL injection vulnerability in Directus versions prior to 12.1.0 affecting PostgreSQL with PostGIS.
How do I fix CVE-2026-10716?
To fix CVE-2026-10716, upgrade your Directus installation to version 12.1.0 or later.
Who is affected by CVE-2026-10716?
Any Directus installation using versions below 12.1.0 with PostgreSQL and PostGIS enabled is vulnerable to CVE-2026-10716.
What type of vulnerability is CVE-2026-10716?
CVE-2026-10716 is classified as an SQL Injection vulnerability.