Beveiligingsadvies

CVE-2026-63733

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-20 12:04:30
Laatst bijgewerkt 2026-07-28 01:05:31
Toegewezen door VulnCheck
CVSS-score 5.3
Status PUBLISHED

Beschrijving

SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers with permission to perform a guarded operation can write to tables they lack permission for by embedding CREATE, UPDATE, DELETE, or UPSERT statements in the PERMISSIONS clause, causing unintended writes and data corruption.