CVE-2026-63738: SurrealDB 3.1.0 before 3.1.5 Field Permission Bypass via Traversal
SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through graph-edge or back-reference traversals. Attackers with table-level SELECT access can read field values hidden by field-level permissions by materializing records through graph traversals instead of direct table scans.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.5
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63738?
The severity of CVE-2026-63738 is medium with a score of 5.3.
How do I fix CVE-2026-63738?
To fix CVE-2026-63738, upgrade SurrealDB to version 3.1.5 or later.
What does CVE-2026-63738 exploit?
CVE-2026-63738 exploits a field permission bypass through graph-edge or back-reference traversals in SurrealDB.
What are the potential impacts of CVE-2026-63738?
CVE-2026-63738 allows attackers to access field values that should be hidden due to field-level permissions.
Which version of SurrealDB is vulnerable to CVE-2026-63738?
SurrealDB versions 3.1.0 before 3.1.5 are vulnerable to CVE-2026-63738.