CVE-2026-63757

HIGH

SurrealDB before 3.1.0 Session Hijacking via /rpc sessions

Title source: cna
STIX 2.1

Description

SurrealDB versions before 3.1.0 contain a session hijacking vulnerability where the HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership verification. Unauthenticated attackers can enumerate session UUIDs and impersonate authenticated sessions to read, write, delete data and escalate privileges.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-5qfp-32cf-69jh)
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-5qfp-32cf-69jh
Third Party Advisory third-party-advisory
VulnCheck Advisory: SurrealDB before 3.1.0 Session Hijacking via /rpc sessions
https://www.vulncheck.com/advisories/surrealdb-before-session-hijacking-via-rpc-sessions

Scores

CVSS v3 8.8
EPSS 0.0035
EPSS Percentile 28.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
surrealdb/surrealdb < 3.1.0 (2 CPE variants)
surrealdb/surrealdb 3.1.0
Published Jul 20, 2026
Tracked Since Jul 20, 2026