CVE-2026-63763
Last modified
CVE-2026-63763 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or closures. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or closures. Because these are executed in the context of the invoking/querying user rather than their creator, an attacker can plant malicious logic that executes with a higher-privileged user's permissions when that user reads or writes the affected record. This can lead to full privilege escalation, including creation of a root owner and server takeover.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Surrealdb | Surrealdb | < 2.5.0 | — |
| Surrealdb | Surrealdb | 3.0.0 | Alpha1 |
References
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-3v2x-9xcv-2v2vMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-63763?
How severe is CVE-2026-63763?
How do I fix CVE-2026-63763?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-63758SurrealDB versions before 3.1.0 contain an authorization byp…5.4
- CVE-2026-63759SurrealDB before 3.1.0 fails to enforce recursion depth limi…7.1
- CVE-2026-6376A weakness in SpiceJet’s public booking retrieval page permi…8.7
- CVE-2026-63760SurrealDB before 3.1.0 fails to enforce the configured recur…8.7
- CVE-2026-63761SurrealDB before 3.1.0 silently substitutes the ES384 algori…5.3
- CVE-2026-63762SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains …6.5
- CVE-2026-63764LMDeploy through 0.14.0, fixed in commit 03c3130, contains a…8.6
- CVE-2026-63765Chatwoot before 4.16.0 contains an authentication bypass vul…8.8
- CVE-2026-63766GPT-SoVITS through 20250606v2pro contains an OS command inje…9.8
- CVE-2026-63767ktransformers through 0.6.3, fixed in commit def0f93, contai…9.8
- CVE-2026-63768cal.diy through 6.2.0 contains an open redirect vulnerabilit…5.3
- CVE-2026-63769Huginn through 2022.08.18 contains a server-side request for…7.7
Are you affected by CVE-2026-63763?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
