Junglewise Threat Intelligence

CVE-2026-63749: SurrealDB authentication bypass in LIVE SELECT subscriptions

CVE-2026-63749 · Severity: medium · CVSS 4.3 · Published 2026-07-20

Vendors: SurrealDB.

Executive brief

SurrealDB, a multi-model cloud database, contains a flaw in its real-time subscription feature. An authenticated user can bypass security rules to receive notifications about data they are not authorized to see. This could lead to the unauthorized disclosure of sensitive records within a database table.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in SurrealDB's LIVE SELECT mechanism. When a permission expression references system variables like $value, $before, $after, or $event, an authenticated user can shadow these variables with their own values using a LET statement before registering a subscription. Because the database engine prioritized user-defined variables over system-derived document context during notification evaluation, the permission check (e.g., WHERE $auth.id IN $value) can be forced to return true for all records. This allows a subscriber to receive real-time updates for records that should be hidden by SELECT permissions. The issue is fixed in version 3.1.0 by ensuring system parameters take precedence over user-defined variables.

Affected products

  • SurrealDB SurrealDB < 3.1.0

Timeline

  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-07-20: disclosed: NVD publication date

References