CVE-2026-63751
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated use
CVSS
4.3
Medium
EPSS
0.3%
p22
KEV
—
Exploit Today
6
0-100
Published: Jul 20, 2026 · Last modified: Jul 22, 2026 · CWE-863
0.2%EPSS · 30 days0.3%
2026-08-102026-09-07
SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated users to read protected fields. Attackers can use UPDATE PATCH with an empty from pointer in copy or move operations to duplicate all record fields, including those restricted by field-level SELECT permissions, into attacker-chosen destination fields.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-865448.1 HIG—
——0knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace to modify permission configurations and escalate privileges on subsequent calls.15hCVE-2026-864377.2 HIG—
——0Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives over the live application source code. Attackers can upload a malicious archive containing modified application files such as routes/web.php with embedded system commands, which execute as the web server user with access to environment secrets and database credentials.16hCVE-2026-864987.7 HIG—
——0In JetBrains YouTrack before 2025.3.160480,
2026.1.14047 pUT requests on link sub-resources allowed modification linked entities without update permission3hCVE-2026-864936.5 MED—
——0In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed read-only users to create and modify whiteboard cards3hCVE-2026-864906.5 MED—
——0In JetBrains YouTrack before 2026.2.18634 improper permission checks allowed overwriting of bundled apps via the app import endpoint3hCVE-2026-864873.1 LOW—
——0In JetBrains YouTrack before 2026.2.18634 a crafted WebSocket message allowed read-only whiteboard users to modify canvas content3h