VYPR
Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 28, 2026

SurrealDB before 3.1.0 Information Disclosure via Error Messages

CVE-2026-63748

Description

SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or extend operations on hidden fields to embed raw operand values in error responses, bypassing field-level access controls.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.