What is CVE-2026-10716?
Directus contains an authenticated SQL injection vulnerability in the collection creation flow when using PostgreSQL with PostGIS enabled. An administrator can exploit this by injecting SQL syntax into the `fields[].type` value for a geometry field. Users are strongly advised to upgrade Directus to the latest patched version immediately.
Azərbaycanca: Directus platformasının PostgreSQL və PostGIS aktiv olduğu mühitlərdə autentifikasiya olunmuş administratorun SQL injection həyata keçirməsinə imkan verən boşluqdur. Bu zəiflik, kolleksiya yaradılması zamanı `geometry` tipli sahənin tip parametrinə SQL sintaksisi əlavə edərək istismar edilir. İstifadəçilərə təcili olaraq Directus-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
In which database environments is the CVE-2026-10716 vulnerability in Directus exploitable?
This vulnerability is exploitable only in environments where PostgreSQL is used as the database with the PostGIS extension enabled.
What mitigation step is recommended to protect against CVE-2026-10716?
Users are strongly advised to upgrade Directus to the latest patched version immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.