CVE-2026-63309
MEDIUMSurrealDB < 3.1.5 Information Disclosure via ORDER BY
Title source: cnaDescription
SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to leak the relative ordering of restricted field values. Attackers can issue ORDER BY queries on indexed restricted fields to recover the hidden values' sort order across records, even though the field itself returns null as intended.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-h4h3-3rfj-x6fq)
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-h4h3-3rfj-x6fq
Release Notes release-notes
Release Notes
https://github.com/surrealdb/surrealdb/releases/tag/v3.1.5
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/surrealdb-information-disclosure-via-order-by
Scores
CVSS v3
4.3
EPSS
0.0019
EPSS Percentile
9.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (2)
surrealdb/surrealdb
3.0.0 - 3.1.5
surrealdb/surrealdb
3.1.5
Published
Jul 17, 2026
Tracked Since
Jul 17, 2026