CVE-2026-63751

SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated users to read protected fields. Attackers can use UPDATE PATCH with an empty from pointer in copy or move operations to duplicate all record fields, including those restricted by field-level SELECT permissions, into attacker-chosen destination fields.
Configurations

Configuration 1 (hide)

cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

History

22 Jul 2026, 15:39

Type Values Removed Values Added
First Time Surrealdb
Surrealdb surrealdb
CPE cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*
References () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-fpxg-5xmv-922m - () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-fpxg-5xmv-922m - Vendor Advisory, Mitigation
References () https://www.vulncheck.com/advisories/surrealdb-before-field-permission-bypass-via-json-patch - () https://www.vulncheck.com/advisories/surrealdb-before-field-permission-bypass-via-json-patch - Third Party Advisory

20 Jul 2026, 12:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 12:19

Updated : 2026-07-22 15:39


NVD link : CVE-2026-63751

Mitre link : CVE-2026-63751

CVE.ORG link : CVE-2026-63751


JSON object : View

Products Affected

surrealdb

  • surrealdb
CWE
CWE-863

Incorrect Authorization