CVE-2026-63756
SurrealDB versions before 3.1.0 contain a race condition in the HTTP /rpc endpoint that lets unauthenticated users hijack authenticated sessions. This flaw allows attackers to perform actions with the privileges of a logged‑in user. The vulnerability is critical because it can be exploited without any authentication.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
SurrealDB versions prior to 3.1.0 that use the /rpc endpoint.
Real-world impact
An attacker could take over a user's session and execute privileged operations, effectively gaining the same access as the legitimate user.
Why this severity
The CVSS score of 9.2 reflects the high impact of hijacking user privileges (high confidentiality, integrity, availability impact) combined with the difficulty of exploitation (high attack complexity) and the lack of required privileges or user interaction.
What to do about it
- ›Avoid using the /rpc endpoint until a patch is released.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- github.com/surrealdb/surrealdb/securit…vendor advisory
- vulncheck.com/advisories/surrealdb-before…third party advisory