PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10716 Directus CVE debrief

CVE-2026-10716 is an authenticated SQL injection vulnerability in Directus when using PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with 'geometry' but contains attacker-controlled SQL syntax after the geometry subtype. This issue affects Directus versions before 12.1.0. Administrators and users of Directus instances with PostgreSQL and PostGIS enabled should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was published on 2026-08-05T18:16:52.410Z and has not been modified since then. To address this vulnerability, administrators should verify their instance's collection creation flow for potential SQL injection vulnerabilities and ensure the upgrade to version 12.1.0 or later.

Vendor
Directus
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-08-05
Advisory published
2026-08-05
Advisory updated
2026-08-05

Who should care

Administrators and users of Directus instances with PostgreSQL and PostGIS enabled should be aware of this vulnerability and take necessary actions to mitigate it. This includes verifying their instance's collection creation flow for potential SQL injection vulnerabilities and ensuring the upgrade to version 12.1.0 or later. Security teams and vulnerability management teams should also be aware of this vulnerability and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Operators and platform administrators should review compensating controls for exposed systems while remediation is scheduled and verified. They should also check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Asset inventory management and source tracking are also crucial in addressing this vulnerability. Monitoring and compensating controls can help detect and prevent potential attacks. Rolling back changes and verifying the integrity of the system are also essential steps in mitigating this vulnerability. The goal is to ensure the security and integrity of Directus instances and prevent potential attacks. By taking these steps, administrators and users can minimize the risk associated with this vulnerability and protect their systems from potential attacks. This requires a coordinated effort from various stakeholders, including administrators, security teams, and vulnerability management teams. Effective communication and collaboration are essential in addressing this vulnerability and ensuring the security of Directus instances. By working together, organizations can minimize the risk associated with this vulnerability and protect their systems from potential attacks. The CVE record provides valuable information about the vulnerability, including its description, CVSS score, and affected versions. By reviewing this information and taking the necessary steps, administrators and users can ensure the security and integrity of their Directus instances. CVE-2026-10716 is a serious vulnerability that can

Technical summary

CVE-2026-10716 is an authenticated SQL injection vulnerability in the Directus collection creation flow when using PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with 'geometry' but contains attacker-controlled SQL syntax after the geometry subtype. This issue affects Directus versions before 12.1.0. To mitigate this vulnerability, administrators should verify their instance's collection creation flow for potential SQL injection vulnerabilities and ensure the upgrade to version 12.1.0 or later. Additionally, administrators should monitor for suspicious collection creation activity.

Defensive priority

Administrators using Directus with PostgreSQL and PostGIS should verify their instance's collection creation flow for potential SQL injection vulnerabilities and ensure the upgrade to version 12.1.0 or later.

Recommended defensive actions

  • Verify instance's collection creation flow for potential SQL injection vulnerabilities
  • Ensure the upgrade to Directus version 12.1.0 or later
  • Monitor for suspicious collection creation activity
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE-2026-10716 record indicates an authenticated SQL injection vulnerability in Directus when using PostgreSQL with PostGIS enabled. An administrator can create a collection with a geometry field whose fields[].type value starts with 'geometry' but contains attacker-controlled SQL syntax after the geometry subtype. This issue affects Directus versions before 12.1.0.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T18:16:52.410Z and has not been modified since then.