Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63733

SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers with permission to perform a guarded operation can write to tables they lack permission for by embedding CREATE, UPDATE, DELETE, or UPSERT statements in the PERMISSIONS clause, causing unintended writes and data corruption.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 10.3%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2026-63733


Contact Us

Shodan ® - All rights reserved