SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE permission. Attackers can issue a RELATE statement with a SET id clause pointing to an existing edge id, causing the storage layer to silently overwrite the target record instead of rejecting the operation.
References
| Link | Resource |
|---|---|
| https://github.com/surrealdb/surrealdb/security/advisories/GHSA-f82j-v89j-mf86 | Vendor Advisory Mitigation |
| https://www.vulncheck.com/advisories/surrealdb-before-relate-statement-record-overwrite | Third Party Advisory |
Configurations
History
22 Jul 2026, 15:39
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Surrealdb
Surrealdb surrealdb |
|
| CPE | cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:* | |
| References | () https://github.com/surrealdb/surrealdb/security/advisories/GHSA-f82j-v89j-mf86 - Vendor Advisory, Mitigation | |
| References | () https://www.vulncheck.com/advisories/surrealdb-before-relate-statement-record-overwrite - Third Party Advisory |
20 Jul 2026, 12:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-20 12:19
Updated : 2026-07-22 15:39
NVD link : CVE-2026-63752
Mitre link : CVE-2026-63752
CVE.ORG link : CVE-2026-63752
JSON object : View
Products Affected
surrealdb
- surrealdb
CWE
CWE-285
Improper Authorization
