PatchSiren cyber security CVE debrief
CVE-2026-63757 surrealdb CVE debrief
CVE-2026-63757 is a session hijacking vulnerability in SurrealDB versions before 3.1.0. The HTTP /rpc sessions method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership verification. This allows unauthenticated attackers to enumerate session UUIDs and impersonate authenticated sessions to read, write, delete data and escalate privileges. The vulnerability has a CVSS score of 8.7 and is classified as HIGH severity. Users of SurrealDB versions before 3.1.0 should be aware of this vulnerability and take steps to mitigate it.
- Vendor
- surrealdb
- Product
- Unknown
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-07-22
Who should care
Users of SurrealDB versions before 3.1.0 should be aware of this vulnerability and take steps to mitigate it. This includes upgrading to version 3.1.0 or later, and implementing additional security measures such as monitoring for suspicious activity and restricting access to sensitive data. Operators, platform administrators, vulnerability management teams, and security teams should review the official advisory and CVE record to validate affected scope, severity, and vendor guidance.
Technical summary
The vulnerability exists in the HTTP /rpc sessions method of SurrealDB versions before 3.1.0. This method returns attached session UUIDs without authentication and accepts arbitrary session fields with no ownership verification. An unauthenticated attacker can exploit this vulnerability to enumerate session UUIDs and impersonate authenticated sessions, allowing them to read, write, delete data and escalate privileges. The vulnerability is caused by a lack of authentication and ownership verification in the HTTP /rpc sessions method.
Defensive priority
High
Recommended defensive actions
- Upgrade to SurrealDB version 3.1.0 or later
- Implement monitoring for suspicious activity
- Restrict access to sensitive data
- Verify session UUIDs and ownership
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-07-20T12:19:45.747Z and was last modified on 2026-07-21T18:37:56.803Z. The NVD entry is currently Awaiting Analysis. This information is based on the provided source corpus and may be subject to change as new information becomes available. Defenders should verify the accuracy of this information and review the official CVE record and NVD entry for the latest details.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T12:19:45.747Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.