CVE-2026-63741
MEDIUMSurrealDB before 3.1.0 Authentication Bypass via USE statement
Title source: cnaDescription
SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauthenticated attackers can create arbitrary namespaces and databases by issuing USE commands, bypassing authorization checks in the RPC use method and SurrealQL executor.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-wp87-mgvq-5j93)
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-wp87-mgvq-5j93
Third Party Advisory third-party-advisory
VulnCheck Advisory: SurrealDB before 3.1.0 Authentication Bypass via USE statement
https://www.vulncheck.com/advisories/surrealdb-before-authentication-bypass-via-use-statement
Scores
CVSS v3
6.5
EPSS
0.0027
EPSS Percentile
18.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
surrealdb/surrealdb
< 3.1.0 (2 CPE variants)
surrealdb/surrealdb
3.1.0
Published
Jul 20, 2026
Tracked Since
Jul 20, 2026