CVE-2026-63751
MEDIUMSurrealDB before 3.1.0 Field Permission Bypass via JSON Patch
Title source: cnaDescription
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated users to read protected fields. Attackers can use UPDATE PATCH with an empty from pointer in copy or move operations to duplicate all record fields, including those restricted by field-level SELECT permissions, into attacker-chosen destination fields.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-fpxg-5xmv-922m)
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-fpxg-5xmv-922m
Third Party Advisory third-party-advisory
VulnCheck Advisory: SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch
https://www.vulncheck.com/advisories/surrealdb-before-field-permission-bypass-via-json-patch
Scores
CVSS v3
4.3
EPSS
0.0017
EPSS Percentile
7.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-863
Status
published
Products (2)
surrealdb/surrealdb
< 3.1.0 (2 CPE variants)
surrealdb/surrealdb
3.1.0
Published
Jul 20, 2026
Tracked Since
Jul 20, 2026