Array Element Permission Bypass in SurrealDB
CVE-2026-63740

7.1HIGH

Key Information:

Vendor

Surrealdb

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63740?

SurrealDB versions prior to 3.1.4 exhibit a significant flaw in the enforcement of SELECT permissions for array elements. This vulnerability allows recorded users to access and leak array elements that should be restricted, effectively bypassing element-level permissions. Malicious actors with record scope access can exploit this vulnerability through incorrect index handling during permission filtering, leading to potential unauthorized visibility of sensitive data.

Affected Version(s)

surrealdb 0 < 3.1.4

surrealdb 3.1.4

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

msanchezdev
.