CVE-2026-63745: SurrealDB before 3.1.0 Authorization Bypass via Composite Record-id
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability where authenticated users can spoof composite record-id field values by writing to editable body fields. Attackers can bypass permission rules that gate access on id components like tenant isolation by setting same-named body fields to spoofed values that permission checks incorrectly read instead of the immutable id key.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63745?
CVE-2026-63745 has a medium severity rating of 5.3.
How do I fix CVE-2026-63745?
To fix CVE-2026-63745, upgrade SurrealDB to version 3.1.0 or later.
What does CVE-2026-63745 affect?
CVE-2026-63745 affects SurrealDB versions prior to 3.1.0.
What type of vulnerability is CVE-2026-63745?
CVE-2026-63745 is an authorization bypass vulnerability.
How can attackers exploit CVE-2026-63745?
Attackers can exploit CVE-2026-63745 by spoofing the composite record-id field values to bypass permission rules.