Medium severity6.5NVD Advisory· Published Jul 20, 2026· Updated Jul 23, 2026
CVE-2026-63741
CVE-2026-63741
Description
SurrealDB versions before 3.1.0 fail to validate DEFINE NAMESPACE or DEFINE DATABASE permissions when processing USE NS and USE DB statements. Unauthenticated attackers can create arbitrary namespaces and databases by issuing USE commands, bypassing authorization checks in the RPC use method and SurrealQL executor.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- github.com/surrealdb/surrealdb/security/advisories/GHSA-wp87-mgvq-5j93nvdMitigationVendor Advisory
- www.vulncheck.com/advisories/surrealdb-before-authentication-bypass-via-use-statementnvdThird Party Advisory
News mentions
0No linked articles in our index yet.