PT-2026-61551 · Surrealdb · Surrealdb

·

CVE-2026-63735

·

Published

2026-07-20

·

Updated

2026-09-05

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 3.2.0
Description Custom API routes fail to validate namespace and database scope, which allows authenticated users to invoke endpoints across different namespaces or databases. An attacker with valid credentials for any namespace or database can access custom API endpoints belonging to other tenants by specifying the target scope within the URL path. This can lead to the unauthorized reading of sensitive data or the triggering of unintended operations.
Recommendations Update SurrealDB to version 3.2.0 or later.

Fix

IDOR

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63735
GHSA-3F6W-45Q9-V69M
GHSA-848M-R628-VRXW

Affected Products

Surrealdb