← Vulnerability feed

Vulnerability record · CVE-2026-63740 · published 20 July 2026

CVE-2026-63740: Surrealdb incorrect authorization vulnerability

Surrealdb · Surrealdb

SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elements instead of hiding them. Attackers with record scope access can read array elements that element-level permissions should deny by exploiting incorrect index handling during permission filtering.

7.1 CVSS 4.0 High EPSS 0.36% · top 73.0% CWE-863 · Incorrect authorization
7.1CVSS 4.0 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
22 Jul 2026Last modified by NVD

Description

SurrealDB versions before 3.1.4 fail to properly enforce SELECT permissions on array elements (field.*) for record users, leaking denied array elements instead of hiding them. Attackers with record scope access can read array elements that element-level permissions should deny by exploiting incorrect index handling during permission filtering.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-63740 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2025-71392Surrealdb command injection vulnerabilitySurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command.…EPSS 0.44%9.2CVE-2026-63756Surrealdb race condition vulnerabilitySurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to …EPSS 0.37%9.0CVE-2024-58366Delskayn rquickjs vulnerabilitySurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when scripting is enabled. Attackers wit…EPSS 0.58%8.7CVE-2026-63760Surrealdb vulnerabilitySurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and JSON parser when processing nested braces, brackets, or…EPSS 0.52%8.7CVE-2026-63757Surrealdb missing authentication for critical function vulnerabilitySurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without …EPSS 0.54%8.7CVE-2026-63747Surrealdb vulnerabilitySurrealDB versions before 3.1.0 contain a denial of service vulnerability in the RPC use handler that panics when db is set without a namespace. Unau…EPSS 0.52%8.7CVE-2024-58362Surrealdb vulnerabilitySurrealDB before 1.5.5 (and 2.0.0-beta before 2.0.0-beta.3) accepts an arbitrary object in the signin and signup operations of the RPC API without re…EPSS 0.64%8.7CVE-2024-58368Surrealdb vulnerabilitySurrealDB versions before 1.1.0 fail to properly parse the ID, DB, and NS headers in HTTP REST API requests containing special characters. Unauthenti…EPSS 0.65%

Source: NIST National Vulnerability Database (record CVE-2026-63740), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.