CVE-2026-10716

HIGH CVSS 4.0: 7.5 EPSS 0.31%
Updated Aug 05, 2026
PostgreSQL
Parameter Value
CVSS 7.5 (HIGH)
Affected Versions before 12.1.0.
Type CWE-89 (SQL Injection)
Vendor PostgreSQL
Public PoC No

Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with geometry but contains attacker-controlled SQL syntax after the geometry subtype.This issue affects Directus: before 12.1.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)