CVE-2026-63756: SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition
SurrealDB versions before 3.1.0 contain a time-of-check/time-of-use race condition in the HTTP /rpc endpoint that allows unauthenticated requests to inherit authenticated session state. Unauthenticated attackers can send concurrent requests to the /rpc endpoint while legitimate authenticated traffic is active to execute operations with hijacked user privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0 - Compensating control
Restrict network access to the SurrealDB HTTP /rpc endpoint so unauthenticated clients cannot reach it (e.g., allowlist trusted IPs/VPN; block public access) until the upgrade to 3.1.0 is completed.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63756?
The severity of CVE-2026-63756 is critical with a score of 9.2.
How does CVE-2026-63756 affect SurrealDB?
CVE-2026-63756 allows unauthenticated attackers to exploit a race condition to inherit authenticated session state.
How do I fix CVE-2026-63756?
To fix CVE-2026-63756, update SurrealDB to version 3.1.0 or later.
What type of vulnerability is CVE-2026-63756?
CVE-2026-63756 is classified as a Race Condition vulnerability.
When was CVE-2026-63756 published?
CVE-2026-63756 was published on July 20, 2026.