PT-2026-61572 · Surrealdb · Surrealdb

·

CVE-2026-63756

·

Published

2026-07-20

·

Updated

2026-07-21

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 3.1.0
Description A time-of-check/time-of-use race condition exists in the HTTP '/rpc' endpoint. This flaw allows unauthenticated requests to inherit the authenticated session state of other users. An attacker can send concurrent requests to the '/rpc' endpoint during active authenticated traffic to execute operations using hijacked user privileges. A time-of-check/time-of-use race condition is a software bug where a system checks the state of a resource before using it, but the state changes between the check and the use.
Recommendations Update SurrealDB to version 3.1.0 or later. As a temporary mitigation, restrict access to the '/rpc' endpoint to trusted networks.

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63756

Affected Products

Surrealdb