A vulnerability categorized as problematic has been discovered in Directus up to 12.0.x. This issue affects some unknown processing of the component Collection Creation. Such manipulation of the argument fields[] leads to sql injection.
This vulnerability is traded as CVE-2026-10716. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.