Information Disclosure Vulnerability in SurrealDB by SurrealDB Inc.
CVE-2026-63748

5.3MEDIUM

Key Information:

Vendor

Surrealdb

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63748?

SurrealDB, prior to version 3.1.0, is susceptible to an information disclosure issue that allows authenticated users with UPDATE privileges to gain access to field values obscured by field-level SELECT permissions. This vulnerability can be exploited when an attacker triggers arithmetic or extension operations on fields meant to be hidden, resulting in the exposure of sensitive data through error messages that disclose raw operand values, thus circumventing established access controls.

Affected Version(s)

surrealdb 0 < 3.1.0

surrealdb 3.1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.