CVE-2026-63763

EUVD-2026-45934
SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation vulnerability. Unprivileged users (e.g., those with the database editor role) can create or modify fields containing futures, functions, or closures. Because these are executed in the context of the invoking/querying user rather than their creator, an attacker can plant malicious logic that executes with a higher-privileged user's permissions when that user reads or writes the affected record. This can lead to full privilege escalation, including creation of a root owner and server takeover.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 40.71%
Affected Products (NVD)
VendorProductVersion
surrealdbsurrealdb
𝑥
< 2.5.0
surrealdbsurrealdb
3.0.0:alpha1
surrealdbsurrealdb
3.0.0:alpha10
surrealdbsurrealdb
3.0.0:alpha11
surrealdbsurrealdb
3.0.0:alpha12
surrealdbsurrealdb
3.0.0:alpha13
surrealdbsurrealdb
3.0.0:alpha14
surrealdbsurrealdb
3.0.0:alpha16
surrealdbsurrealdb
3.0.0:alpha17
surrealdbsurrealdb
3.0.0:alpha18
surrealdbsurrealdb
3.0.0:alpha2
surrealdbsurrealdb
3.0.0:alpha3
surrealdbsurrealdb
3.0.0:alpha4
surrealdbsurrealdb
3.0.0:alpha5
surrealdbsurrealdb
3.0.0:alpha6
surrealdbsurrealdb
3.0.0:alpha7
surrealdbsurrealdb
3.0.0:alpha8
surrealdbsurrealdb
3.0.0:alpha9
surrealdbsurrealdb
3.0.0:beta1
surrealdbsurrealdb
3.0.0:beta2
𝑥
= Vulnerable software versions