Authentication Bypass in SurrealDB Affects Real-Time Notification Systems
CVE-2026-63753

5.3MEDIUM

Key Information:

Vendor

Surrealdb

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63753?

SurrealDB versions prior to 3.1.0 contain a vulnerability where the system fails to properly refresh the authentication state during LIVE SELECT subscriptions when there are changes in session status. This oversight allows attackers to continue receiving real-time notifications even after their session credentials have been revoked or expired, remaining connected until the connection is terminated. This incident raises significant security concerns for applications relying on real-time data updates.

Affected Version(s)

surrealdb 0 < 3.1.0

surrealdb 3.1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LucyEgan
addcontent
.