Array Element Permission Bypass in SurrealDB
CVE-2026-63740
7.1HIGH
What is CVE-2026-63740?
SurrealDB versions prior to 3.1.4 exhibit a significant flaw in the enforcement of SELECT permissions for array elements. This vulnerability allows recorded users to access and leak array elements that should be restricted, effectively bypassing element-level permissions. Malicious actors with record scope access can exploit this vulnerability through incorrect index handling during permission filtering, leading to potential unauthorized visibility of sensitive data.
Affected Version(s)
surrealdb 0 < 3.1.4
surrealdb 3.1.4
