CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-63739

highCVSS 7.7covered by 1 sourcefirst seen 2026-07-20
SurrealDB before 3.1.5 contains an arbitrary file read vulnerability in the DEFINE ANALYZER mapper filter that allows database users with EDITOR or OWNER roles to read files accessible to the SurrealDB process. Attackers can specify arbitrary file paths in the mapper filter and retrieve file contents through query error messages when the SURREAL_FILE_ALLOWLIST is empty or not configured.

⚡ Watch CVE-2026-63739

Get an email if CVE-2026-63739 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-63739

CVE.org record

Embed the live status

CVE-2026-63739 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-63739 status](https://www.csirts.com/badge/CVE-2026-63739)](https://www.csirts.com/cve/CVE-2026-63739)