CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-63758

mediumCVSS 5.4covered by 1 sourcefirst seen 2026-07-20
SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL statement that allows authenticated database users to terminate other users' LIVE SELECT subscriptions. Attackers can issue KILL statements with target live query UUIDs to disrupt real-time data subscriptions of other users without ownership verification.

⚡ Watch CVE-2026-63758

Get an email if CVE-2026-63758 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-63758

CVE.org record

Embed the live status

CVE-2026-63758 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-63758 status](https://www.csirts.com/badge/CVE-2026-63758)](https://www.csirts.com/cve/CVE-2026-63758)