CVE-2026-63752: SurrealDB before 3.1.0 RELATE Statement Record Overwrite
SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE permission. Attackers can issue a RELATE statement with a SET id clause pointing to an existing edge id, causing the storage layer to silently overwrite the target record instead of rejecting the operation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63752?
The severity of CVE-2026-63752 is rated as medium with a score of 5.3.
How do I fix CVE-2026-63752?
To mitigate CVE-2026-63752, upgrade to SurrealDB version 3.1.0 or later.
What type of vulnerability is CVE-2026-63752?
CVE-2026-63752 is an authorization bypass vulnerability affecting the RELATE statement in SurrealDB.
Who is affected by CVE-2026-63752?
Authenticated users with CREATE permission on SurrealDB versions before 3.1.0 are affected by CVE-2026-63752.
What can attackers do with CVE-2026-63752?
Attackers can overwrite existing edge records without UPDATE permission by using the RELATE statement with an id clause targeting those records.