SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-63749

MEDIUM · CVSS 4.3 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 3.1.0 are vulnerable to an authentication bypass in LIVE SELECT subscriptions, allowing authenticated users to manipulate permission expressions and access records that should be restricted. This flaw enables attackers to receive notifications for sensitive data, undermining the integrity of access controls. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-63749
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%

Original NVD Description

SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permission expressions referencing $value, $before, $after, or $event are evaluated against attacker-controlled bindings instead of actual documents. Authenticated subscribers can bind chosen values to these parameter names and register LIVE SELECT queries to receive notifications for records that SELECT permission expressions should have hidden.

Related CVEs

Other vulnerabilities affecting the same vendor(s)