Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Msanchezdev

#43467of 56,326
6.5Total CVSS
Vulnerabilities · 1
PT-2026-61556
6.5
2026-07-20
Surrealdb · Surrealdb · CVE-2026-63740
**Name of the Vulnerable Software and Affected Versions** SurrealDB versions prior to 3.1.4 **Description** Incorrect index handling during permission filtering allows attackers with record scope access to read array elements that should be restricted. This occurs when the system fails to properly enforce SELECT permissions on array elements (field.*) for record users, resulting in the leakage of denied array elements instead of hiding them. **Recommendations** Update SurrealDB to version 3.1.4 or later.