CVE-2026-63757: SurrealDB before 3.1.0 Session Hijacking via /rpc sessions
SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership verification. Unauthenticated attackers can enumerate session UUIDs and impersonate authenticated sessions to read, write, delete data and escalate privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63757?
The severity of CVE-2026-63757 is rated high with a score of 8.8.
How do I fix CVE-2026-63757?
To fix CVE-2026-63757, upgrade SurrealDB to version 3.1.0 or later.
What systems are affected by CVE-2026-63757?
CVE-2026-63757 affects SurrealDB versions prior to 3.1.0.
What type of vulnerability is CVE-2026-63757?
CVE-2026-63757 is a session hijacking vulnerability.
Who can exploit CVE-2026-63757?
Unauthenticated attackers can exploit CVE-2026-63757 to enumerate session UUIDs and potentially impersonate users.