CVE-2026-63742: SurrealDB before 3.1.0 Field Permission Bypass via Indexed COUNT
SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths. Attackers can execute COUNT queries on indexed fields with field-level SELECT restrictions to confirm or recover restricted field values through repeated guesses.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0 - Compensating control
Until SurrealDB is upgraded to 3.1.0, mitigate field permission bypass through indexed COUNT fast paths by blocking or restricting usage of COUNT queries on indexed fields where field-level SELECT restrictions are relied upon.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63742?
The severity of CVE-2026-63742 is medium, rated at 5.3 on the CVSS scale.
How do I fix CVE-2026-63742?
To fix CVE-2026-63742, upgrade your SurrealDB to version 3.1.0 or later.
What type of vulnerability is CVE-2026-63742?
CVE-2026-63742 is a field-level SELECT permission bypass vulnerability.
What could an attacker achieve by exploiting CVE-2026-63742?
An attacker could execute COUNT queries on indexed fields to confirm or recover restricted field values.
Which software is affected by CVE-2026-63742?
SurrealDB versions before 3.1.0 are affected by CVE-2026-63742.