{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/surrealdb-before-3.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-63757"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SurrealDB (before 3.1.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","session-hijacking","privilege-escalation","data-exfiltration","denial-of-service","webserver","json-parsing"],"_cs_type":"threat","_cs_vendors":["SurrealDB"],"content_html":"\u003cp\u003eCVE-2026-63757 details a critical session hijacking vulnerability affecting SurrealDB versions released prior to 3.1.0. This flaw specifically resides in the HTTP /rpc sessions method, which incorrectly returns attached session UUIDs to unauthenticated users and allows arbitrary session fields to be accepted without ownership verification. Exploitation enables an unauthenticated attacker to enumerate active session UUIDs, subsequently impersonating authenticated users within the SurrealDB instance. This unauthorized access allows them to perform read, write, and delete operations on data, ultimately facilitating privilege escalation within the database. The vulnerability poses a significant risk to the integrity and confidentiality of data stored in affected SurrealDB deployments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn unauthenticated attacker sends an HTTP request to the \u003ccode\u003e/rpc sessions\u003c/code\u003e endpoint of a vulnerable SurrealDB instance.\u003c/li\u003e\n\u003cli\u003eThe SurrealDB server, due to the vulnerability, responds by exposing active session UUIDs without requiring any authentication.\u003c/li\u003e\n\u003cli\u003eThe attacker collects and enumerates the obtained session UUIDs, identifying potentially authenticated sessions.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts subsequent API requests, incorporating a stolen session UUID to impersonate an authenticated user.\u003c/li\u003e\n\u003cli\u003eWith the impersonated session, the attacker sends unauthorized requests to read, write, or delete data within the SurrealDB instance.\u003c/li\u003e\n\u003cli\u003eThrough persistent unauthorized data manipulation or by leveraging specific data access, the attacker achieves privilege escalation within the database.\u003c/li\u003e\n\u003cli\u003eThe attacker maintains persistent unauthorized access and control over the SurrealDB instance's data and operations.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-63757 leads to complete compromise of the affected SurrealDB instance. Attackers can gain full read, write, and delete capabilities over all stored data, bypassing normal authentication and authorization mechanisms. This directly impacts data confidentiality, integrity, and availability. Furthermore, the ability to escalate privileges means an attacker could potentially gain administrative control over the database, allowing them to manipulate database schemas, user accounts, and potentially extend their access to other connected systems. Organizations using SurrealDB versions prior to 3.1.0 face a critical risk of data theft, data destruction, and unauthorized system access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-63757 immediately by upgrading all SurrealDB instances to version 3.1.0 or later.\u003c/li\u003e\n\u003cli\u003eMonitor webserver logs for unusual or frequent unauthenticated access attempts to the \u003ccode\u003e/rpc sessions\u003c/code\u003e endpoint, especially from external IP addresses.\u003c/li\u003e\n\u003cli\u003eReview all SurrealDB logs for unauthorized data modification or deletion attempts following unauthenticated access to identify potential exploitation of CVE-2026-63757.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-20T12:28:58Z","date_published":"2026-07-20T12:27:57Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-63757-surrealdb-session-hijacking/","summary":"SurrealDB versions prior to 3.1.0 are vulnerable to a session hijacking flaw (CVE-2026-63757) where unauthenticated attackers can enumerate session UUIDs via the HTTP /rpc sessions method and impersonate authenticated sessions to read, write, and delete data, leading to privilege escalation.","title":"CVE-2026-63757: SurrealDB Session Hijacking Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-63757-surrealdb-session-hijacking/"}],"language":"en","title":"CraftedSignal Threat Feed - SurrealDB (Before 3.1.0)","version":"https://jsonfeed.org/version/1.1"}