CVE-2026-63733: Surrealdb

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers with permission to perform a guarded operation can write to tables they lack permission for by embedding CREATE, UPDATE, DELETE, or UPSERT statements in the PERMISSIONS clause, causing unintended writes and data corruption.

Affected products

  • Surrealdb Surrealdb: before 3.2.0 (fixed in 3.2.0)

Published 2026-07-20. Last modified 2026-07-22.