Junglewise Threat Intelligence

CVE-2026-63758: SurrealDB authorization bypass in KILL statement

CVE-2026-63758 · Severity: medium · CVSS 5.4 · Published 2026-07-20

Technologies: surrealdb (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB, a multi-model cloud database, contains a flaw in how it handles real-time data subscriptions. An authenticated user can prematurely terminate the live data feeds of other users, including those with higher privileges, if they know the specific ID of the subscription. This results in a silent disruption of real-time updates for affected users, potentially breaking application functionality or monitoring tools.

Technical details

A missing authorization check in the KILL statement implementation within `core/src/expr/statements/kill.rs` allows authenticated users to terminate any LIVE SELECT subscription in the database. While the system verifies the requester has database-level access, it fails to verify ownership of the specific live query UUID being terminated. An attacker with network access and valid low-privilege credentials can disrupt the availability of real-time data streams for other tenants or administrators. Exploitation requires knowledge of the target live query's randomly generated UUID, which might be obtained through logs or information disclosure. The issue is resolved in version 3.1.0 by adding an ownership verification check.

Affected products

  • surrealdb surrealdb < 3.1.0

Timeline

  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-07-20: disclosed: CVE published to NVD
  • 2026-07-20: patched: Fix confirmed in version 3.1.0

References

Related threats