CVE-2026-63741: SurrealDB before 3.1.0 Authentication Bypass via USE statement
SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauthenticated attackers can create arbitrary namespaces and databases by issuing USE commands, bypassing authorization checks in the RPC use method and SurrealQL executor.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0 - Compensating control
Block or restrict access to SurrealDB RPC endpoints to authenticated/trusted clients until upgrading to version 3.1.0.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63741?
CVE-2026-63741 has a medium severity rating of 6.9.
How do I fix CVE-2026-63741?
To fix CVE-2026-63741, upgrade SurrealDB to version 3.1.0 or later.
What does CVE-2026-63741 affect?
CVE-2026-63741 affects SurrealDB versions before 3.1.0.
What type of vulnerability is CVE-2026-63741?
CVE-2026-63741 is an authentication bypass vulnerability.
What can attackers do with CVE-2026-63741?
Attackers can create arbitrary namespaces and databases by bypassing authorization checks.