Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 28, 2026
SurrealDB before 3.1.0 Authentication Bypass via LIVE Query
CVE-2026-63753
Description
SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications under revoked or expired session credentials until the connection closes.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/surrealdb/surrealdb/security/advisories/GHSA-4m82-p8cx-f94jmitrevendor-advisory
- www.vulncheck.com/advisories/surrealdb-before-authentication-bypass-via-live-querymitrethird-party-advisory
News mentions
0No linked articles in our index yet.