CVE-2026-63746: SurrealDB before 3.1.0 Permission Bypass via Graph Traversal
SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FOR select clause.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63746?
CVE-2026-63746 has a high severity rating of 7.1.
How do I fix CVE-2026-63746?
To fix CVE-2026-63746, upgrade SurrealDB to version 3.1.0 or later.
What type of vulnerability is CVE-2026-63746?
CVE-2026-63746 is classified as a permission bypass vulnerability due to insufficient enforcement of table SELECT permissions.
Who is affected by CVE-2026-63746?
Authenticated users of SurrealDB versions prior to 3.1.0 are affected by CVE-2026-63746.
What can attackers do with CVE-2026-63746?
Attackers can read records from any table reachable through graph edges, bypassing the intended permissions.