Information Disclosure Vulnerability in SurrealDB by SurrealDB Inc.
CVE-2026-63748
5.3MEDIUM
What is CVE-2026-63748?
SurrealDB, prior to version 3.1.0, is susceptible to an information disclosure issue that allows authenticated users with UPDATE privileges to gain access to field values obscured by field-level SELECT permissions. This vulnerability can be exploited when an attacker triggers arithmetic or extension operations on fields meant to be hidden, resulting in the exposure of sensitive data through error messages that disclose raw operand values, thus circumventing established access controls.
Affected Version(s)
surrealdb 0 < 3.1.0
surrealdb 3.1.0
