A vulnerability categorized as problematic has been discovered in Directus up to 12.0.x. This issue affects some unknown processing of the component Collection Creation. Such manipulation of the argument fields[] leads to sql injection.

This vulnerability is traded as CVE-2026-10716. The attack may be launched remotely. There is no exploit available.

It is advisable to upgrade the affected component.