Junglewise Threat Intelligence

CVE-2026-63735: SurrealDB authorization bypass in custom API routes

CVE-2026-63735 · Severity: high · CVSS 8.1 · Published 2026-07-20

Technologies: surrealdb (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB is a multi-tenant database platform that allows administrators to define custom API endpoints with permission rules. An authenticated user with valid credentials to one namespace/database could bypass tenant boundaries by crafting API requests with another tenant's namespace/database in the URL path, allowing them to read data from or modify other tenants' databases. This undermines tenant isolation in shared deployments.

Technical details

The vulnerability exists in SurrealDB's custom API route handler (`/api/{namespace}/{database}/{endpoint}`) and the related `api::invoke()` function. The route extracted namespace and database parameters from the URL and applied them to the caller's session before endpoint resolution, without verifying the authenticated principal had authorization to access those scopes. Because custom API handlers run with permissions disabled (definer's rights), only the endpoint's `PERMISSIONS` clause acted as a gate — which could be `PERMISSIONS FULL` (open to all). The same flaw affected dynamic scope selection via `surreal-ns`/`surreal-db` headers or `USE` statements. An attacker with valid credentials for namespace A could invoke endpoints in namespace B by including B in the URL, reading protected data or triggering writes. Patch introduced scope validation against the caller's authenticated level before endpoint resolution, returning `403 Forbidden` for out-of-scope requests. Fixed in version 3.2.0 and later.

Affected products

  • SurrealDB SurrealDB < 3.2.0

Timeline

  • 2026-09-04: disclosed: Published in GitHub Advisory Database
  • 2026-07-02: patched: Fixed in SurrealDB 3.2.0

References

Related threats