SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2024-58363

MEDIUM · CVSS 6.3 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-18 · Last synced 2026-08-17

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 1.5.4 are vulnerable due to inadequate authentication validation when users switch databases, potentially allowing an attacker with an authenticated session to impersonate another user if their identifiers match. This could lead to unauthorized access and actions within different databases, compromising data integrity and security. Organizations using SurrealDB should prioritize patching to mitigate this risk, especially those managing sensitive or multi-tenant environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2024-58363
Severity
MEDIUM
CVSS
6.3
EPSS
0.19%

Original NVD Description

SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated session can impersonate an unrelated user in a different database if a user record with an identical identifier exists, allowing unauthorized actions if permissions rely solely on the $auth parameter.

Related CVEs

Other vulnerabilities affecting the same vendor(s)