CVE-2026-63748
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field
CVSS
4.3
Medium
EPSS
0.3%
p26
KEV
—
Exploit Today
8
0-100
Published: Jul 20, 2026 · Last modified: Jul 22, 2026 · CWE-209
0.2%EPSS · 30 days0.3%
2026-08-172026-09-14
SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE access can read field values hidden by field-level SELECT permissions through error messages. Attackers can trigger arithmetic or extend operations on hidden fields to embed raw operand values in error responses, bypassing field-level access controls.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-55102——
——0hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, every API method in src/Vault.js passes failed requests through parseAxiosError(), which rethrows the raw AxiosError while retaining AxiosError.config and the equivalent response configuration. These objects can contain the X-Vault-Token request header and err.config.data request body, including submitted passwords or secret values. When a consuming application records the caught exception through console logging, structured loggers, monitoring, crash reporting, or an application performance monitoring service, the live Vault token and request secrets can be stored in plaintext and exposed to anyone with access to that output. A stolen token can permit unauthorized access to the Vault instance under the token's policies. This issue is fixed in version 0.5.2.22hCVE-2026-663066.5 MED42.3%
——13Generation of error message containing sensitive information in Skype for Business allows an unauthorized attacker to disclose information over a network.7dCVE-2026-696845.5 MED39.3%
——12Generation of error message containing sensitive information in Windows Error Reporting allows an authorized attacker to disclose information locally.7dCVE-2026-695525.7 MED57.5%
——17Generation of error message containing sensitive information in Windows Print Spooler Components allows an authorized attacker to disclose information over a network.7dCVE-2026-692945.5 MED28.1%
——8Generation of error message containing sensitive information in Microsoft COM for Windows allows an authorized attacker to disclose information locally.7dCVE-2026-688865.5 MED39.3%
——12Use after free in Windows Network Connection Broker allows an authorized attacker to disclose information locally.7d