CVE-2026-63748: SurrealDB before 3.1.0 Information Disclosure via Error Messages
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or extend operations on hidden fields to embed raw operand values in error responses, bypassing field-level access controls.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63748?
The severity of CVE-2026-63748 is medium with a score of 5.3.
How do I fix CVE-2026-63748?
To fix CVE-2026-63748, upgrade SurrealDB to version 3.1.0 or later.
What kind of vulnerability is CVE-2026-63748?
CVE-2026-63748 is an information disclosure vulnerability that affects users with UPDATE access in SurrealDB.
Who is affected by CVE-2026-63748?
Authenticated users with UPDATE access in SurrealDB versions before 3.1.0 are affected by CVE-2026-63748.
What can attackers do with CVE-2026-63748?
Attackers can exploit CVE-2026-63748 to read field values hidden by field-level SELECT permissions through error messages.