Medium severity4.3NVD Advisory· Published Jul 20, 2026· Updated Jul 22, 2026
CVE-2026-63751
CVE-2026-63751
Description
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated users to read protected fields. Attackers can use UPDATE PATCH with an empty from pointer in copy or move operations to duplicate all record fields, including those restricted by field-level SELECT permissions, into attacker-chosen destination fields.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
surrealdbcrates.io | < 3.1.0 | 3.1.0 |
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-fpxg-5xmv-922mghsaADVISORY
- github.com/surrealdb/surrealdb/security/advisories/GHSA-fpxg-5xmv-922mnvdVendor AdvisoryMitigationWEB
- nvd.nist.gov/vuln/detail/CVE-2026-63751ghsaADVISORY
- www.vulncheck.com/advisories/surrealdb-before-field-permission-bypass-via-json-patchnvdThird Party AdvisoryWEB
- github.com/surrealdb/surrealdb/commit/56a7a1540d9228f82fd6284c258344e8dcb690fdghsaWEB
News mentions
0No linked articles in our index yet.