Authentication Bypass Vulnerability in SurrealDB by SurrealDB Inc.
CVE-2026-63735

8.6HIGH

Key Information:

Vendor

Surrealdb

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63735?

SurrealDB versions prior to 3.2.0 are vulnerable to an authentication bypass issue due to improper validation of namespaces and database scopes in custom API routes. This flaw allows authenticated users to access and invoke endpoints across different namespaces or databases by manipulating the URL path. As a result, legitimate users can read sensitive data or execute unintended operations that could severely compromise data integrity and security across the platform.

Affected Version(s)

surrealdb 0 < 3.2.0

surrealdb 3.2.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sondt99
.