Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63746

SurrealDB versions before 3.1.0 fail to enforce table SELECT permissions when traversing graph edges or back-references. Authenticated users can read records from any table reachable through graph edges regardless of the target table's PERMISSIONS FOR select clause.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 20.3%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2026-63746


Contact Us

Shodan ® - All rights reserved