CVE-2026-63735 Details
Description
SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databases. Attackers with valid credentials for any namespace/database can access custom API endpoints in other tenants by specifying the target scope in the URL path, reading sensitive data or triggering unintended operations.
A vulnerability exists in SurrealDB versions prior to 3.2.0, where the database and namespace validation in custom API routes is inadequate. This flaw allows authenticated users to access endpoints in different namespaces or databases by manipulating the URL path. Attackers with valid credentials can exploit this to read sensitive data or perform unintended actions on behalf of other tenants.
Users can upgrade to SurrealDB version 3.2.0 or later, where this vulnerability has been patched. Instructions for managing custom API routes and capabilities are available in the SurrealDB documentation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/surrealdb/surrealdb/security/advisories/GHSA-848m-r628-vrxw | [email protected] | MitigationVendor Advisory |
| https://www.vulncheck.com/advisories/surrealdb-before-authentication-bypass-via-custom-api | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| surrealdb surrealdb | < 3.2.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | Initial Analysis | [email protected] |
| Jul 20, 2026 | New CVE Received | [email protected] |