CVE-2026-63758: SurrealDB before 3.1.0 Authorization Bypass via KILL Statement
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. Attackers can issue KILL statements with target live query UUIDs to disrupt real-time data subscriptions of other users without ownership verification.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SurrealDBto a version that resolves this vulnerability.Fixed in 3.1.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63758?
CVE-2026-63758 has a medium severity rating of 5.4.
How do I fix CVE-2026-63758?
To fix CVE-2026-63758, upgrade SurrealDB to version 3.1.0 or later.
What is the impact of CVE-2026-63758?
CVE-2026-63758 allows authenticated users to disrupt other users' live data subscriptions by issuing KILL statements.
Who is affected by CVE-2026-63758?
SurrealDB versions prior to 3.1.0 are affected by CVE-2026-63758.
Is authentication required to exploit CVE-2026-63758?
Yes, an attacker must be an authenticated database user to exploit CVE-2026-63758.