Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63735

SurrealDB versions before 3.2.0 fail to validate namespace and database scope in custom API routes, allowing authenticated users to invoke endpoints in different namespaces/databases. Attackers with valid credentials for any namespace/database can access custom API endpoints in other tenants by specifying the target scope in the URL path, reading sensitive data or triggering unintended operations.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 17.3%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-63735


Contact Us

Shodan ® - All rights reserved