๐Ÿ” CVE Alert

CVE-2026-63763

UNKNOWN 0.0

SurrealDB before 2.5.0 Privilege Escalation via Future Fields

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or closures. Because these are executed in the context of the invoking/querying user rather than their creator, an attacker can plant malicious logic that executes with a higher-privileged user's permissions when that user reads or writes the affected record. This can lead to full privilege escalation, including creation of a root owner and server takeover.

CWE CWE-639
Vendor surrealdb
Product surrealdb
Published Jul 20, 2026
Last Updated Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for surrealdb surrealdb

Be the first to know when new unknown vulnerabilities affecting surrealdb surrealdb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

surrealdb / surrealdb
0 < 2.5.0
surrealdb / surrealdb
0 < 3.0.0-beta.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/surrealdb/surrealdb/security/advisories/GHSA-3v2x-9xcv-2v2v vulncheck.com: https://www.vulncheck.com/advisories/surrealdb-before-privilege-escalation-via-future-fields

Credits

๐Ÿ” cure53 ๐Ÿ” geraname