Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63738

SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through graph-edge or back-reference traversals. Attackers with table-level SELECT access can read field values hidden by field-level permissions by materializing records through graph traversals instead of direct table scans.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 10.6%
CVSS Severity
CVSS v3 Score 4.3
Products affected by CVE-2026-63738


Contact Us

Shodan ® - All rights reserved