Race Condition Vulnerability in SurrealDB by SurrealDB Inc.
CVE-2026-63756

9.2CRITICAL

Key Information:

Vendor

Surrealdb

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-63756?

SurrealDB versions prior to 3.1.0 suffer from a time-of-check/time-of-use race condition on the HTTP /rpc endpoint. This vulnerability enables unauthenticated attackers to exploit concurrent requests during active, legitimate sessions, allowing them to execute operations using the privileges of authenticated users. This could lead to potential unauthorized actions being performed on behalf of legitimate users without their knowledge.

Affected Version(s)

surrealdb 0 < 3.1.0

surrealdb 3.1.0

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

addcontent
.