CVE-2026-63309

SurrealDB before 3.1.5 fail to apply field-level SELECT permissions to ORDER BY clauses, allowing authenticated users to leak the relative ordering of restricted field values. Attackers can issue ORDER BY queries on indexed restricted fields to recover the hidden values' sort order across records, even though the field itself returns null as intended.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-17 17:17

Updated : 2026-07-17 18:28


NVD link : CVE-2026-63309

Mitre link : CVE-2026-63309

CVE.ORG link : CVE-2026-63309


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization