CVE-2026-63751: SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated users to read protected fields. Attackers can use UPDATE PATCH with an empty from pointer in copy or move operations to duplicate all record fields, including those restricted by field-level SELECT permissions, into attacker-chosen destination fields.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0 - Compensating control
Until SurrealDB is upgraded to 3.1.0 or later, avoid/disable JSON Patch update/move/copy operations that could be abused using an empty from pointer, especially for users who should not access field-level restricted data.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63751?
The severity of CVE-2026-63751 is rated medium with a score of 5.3.
How do I fix CVE-2026-63751?
To fix CVE-2026-63751, upgrade SurrealDB to version 3.1.0 or later.
What does CVE-2026-63751 affect?
CVE-2026-63751 affects SurrealDB versions prior to 3.1.0.
Who is impacted by CVE-2026-63751?
Authenticated users of SurrealDB are impacted by CVE-2026-63751 as it allows access to protected fields.
What type of vulnerability is CVE-2026-63751?
CVE-2026-63751 is a field-level permission bypass vulnerability related to JSON Patch operations.