Junglewise Threat Intelligence

CVE-2026-63755: SurrealDB authorization bypass in WHERE clause evaluation

CVE-2026-63755 · Severity: medium · CVSS 6.5 · Published 2026-07-20

Technologies: surrealdb (crates.io). Vendors: crates.io, SurrealDB.

Executive brief

SurrealDB is a multi-model database used for managing structured and unstructured data. A security flaw in how the database processes queries allows an authenticated user to bypass table-level security restrictions and view sensitive data they are not authorized to see. This could lead to the unauthorized exposure of an entire database's contents to any user with basic access.

Technical details

An incorrect authorization flaw (CWE-863) exists in SurrealDB due to the order of operations during query execution. The database evaluates user-supplied clauses (WHERE, SET, MERGE, CONTENT, PATCH) against full record data before enforcing 'PERMISSIONS FOR SELECT WHERE' restrictions. An authenticated attacker, including Record and Scope users, can exploit this by using side-effecting expressions—such as scripting functions, the THROW statement, or timing-based side channels—to exfiltrate record contents. The vulnerability is limited to the database the user is authenticated to and does not cross namespace boundaries. The issue is fixed in version 3.1.0 by ensuring permission checks occur before expression evaluation.

Affected products

  • SurrealDB SurrealDB < 3.1.0

Timeline

  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-07-20: disclosed: NVD publication date
  • 2026-07-20: patched: Version 3.1.0 released

References

Related threats