Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-63758

SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. Attackers can issue KILL statements with target live query UUIDs to disrupt real-time data subscriptions of other users without ownership verification.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 9.2%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2026-63758


Contact Us

Shodan ® - All rights reserved