PatchSiren cyber security CVE debrief
CVE-2026-10716 Directus CVE debrief
CVE-2026-10716 is an authenticated SQL injection vulnerability in Directus when using PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with 'geometry' but contains attacker-controlled SQL syntax after the geometry subtype. This issue affects Directus versions before 12.1.0. Administrators and users of Directus instances with PostgreSQL and PostGIS enabled should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was published on 2026-08-05T18:16:52.410Z and has not been modified since then. To address this vulnerability, administrators should verify their instance's collection creation flow for potential SQL injection vulnerabilities and ensure the upgrade to version 12.1.0 or later.
- Vendor
- Directus
- Product
- Unknown
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-05
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-08-05
- Advisory updated
- 2026-08-05
Who should care
Administrators and users of Directus instances with PostgreSQL and PostGIS enabled should be aware of this vulnerability and take necessary actions to mitigate it. This includes verifying their instance's collection creation flow for potential SQL injection vulnerabilities and ensuring the upgrade to version 12.1.0 or later. Security teams and vulnerability management teams should also be aware of this vulnerability and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Operators and platform administrators should review compensating controls for exposed systems while remediation is scheduled and verified. They should also check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory management and source tracking are also crucial in addressing this vulnerability. Monitoring and compensating controls can help detect and prevent potential attacks. Rolling back changes and verifying the integrity of the system are also essential steps in mitigating this vulnerability. The goal is to ensure the security and integrity of Directus instances and prevent potential attacks. By taking these steps, administrators and users can minimize the risk associated with this vulnerability and protect their systems from potential attacks. This requires a coordinated effort from various stakeholders, including administrators, security teams, and vulnerability management teams. Effective communication and collaboration are essential in addressing this vulnerability and ensuring the security of Directus instances. By working together, organizations can minimize the risk associated with this vulnerability and protect their systems from potential attacks. The CVE record provides valuable information about the vulnerability, including its description, CVSS score, and affected versions. By reviewing this information and taking the necessary steps, administrators and users can ensure the security and integrity of their Directus instances. CVE-2026-10716 is a serious vulnerability that can
Technical summary
CVE-2026-10716 is an authenticated SQL injection vulnerability in the Directus collection creation flow when using PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with 'geometry' but contains attacker-controlled SQL syntax after the geometry subtype. This issue affects Directus versions before 12.1.0. To mitigate this vulnerability, administrators should verify their instance's collection creation flow for potential SQL injection vulnerabilities and ensure the upgrade to version 12.1.0 or later. Additionally, administrators should monitor for suspicious collection creation activity.
Defensive priority
Administrators using Directus with PostgreSQL and PostGIS should verify their instance's collection creation flow for potential SQL injection vulnerabilities and ensure the upgrade to version 12.1.0 or later.
Recommended defensive actions
- Verify instance's collection creation flow for potential SQL injection vulnerabilities
- Ensure the upgrade to Directus version 12.1.0 or later
- Monitor for suspicious collection creation activity
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The CVE-2026-10716 record indicates an authenticated SQL injection vulnerability in Directus when using PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with 'geometry' but contains attacker-controlled SQL syntax after the geometry subtype. This issue affects Directus versions before 12.1.0.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:16:52.410Z and has not been modified since then.