VYPR
Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 28, 2026

SurrealDB before 3.1.0 Authentication Bypass via LIVE Query

CVE-2026-63753

Description

SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.

Affected products

1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.