Race Condition Vulnerability in SurrealDB by SurrealDB Inc.
CVE-2026-63756
9.2CRITICAL
What is CVE-2026-63756?
SurrealDB versions prior to 3.1.0 suffer from a time-of-check/time-of-use race condition on the HTTP /rpc endpoint. This vulnerability enables unauthenticated attackers to exploit concurrent requests during active, legitimate sessions, allowing them to execute operations using the privileges of authenticated users. This could lead to potential unauthorized actions being performed on behalf of legitimate users without their knowledge.
Affected Version(s)
surrealdb 0 < 3.1.0
surrealdb 3.1.0
