CVE-2026-63749: SurrealDB before 3.1.0 Authentication Bypass via LIVE SELECT
SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permission expressions referencing $value, $before, $after, or $event are evaluated against attacker-controlled bindings instead of actual documents. Authenticated subscribers can bind chosen values to these parameter names and register LIVE SELECT queries to receive notifications for records that SELECT permission expressions should have hidden.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63749?
CVE-2026-63749 has a medium severity rating of 5.3.
How do I fix CVE-2026-63749?
To fix CVE-2026-63749, upgrade SurrealDB to version 3.1.0 or later.
What kind of vulnerability is CVE-2026-63749?
CVE-2026-63749 is an authentication bypass vulnerability in SurrealDB.
What can be exploited in CVE-2026-63749?
CVE-2026-63749 allows authenticated users to bypass authentication checks using LIVE SELECT subscriptions.
Which versions of SurrealDB are affected by CVE-2026-63749?
SurrealDB versions before 3.1.0 are affected by CVE-2026-63749.