---
id: CVE-2025-11060
title: >-
  A flaw was found in the live query subscription mechanism of the database
  engine
summary: >-
  A flaw was found in the live query subscription mechanism of the database
  engine. This vulnerability allows record or guest users to observe
  unauthorized records within the same table, bypassing access controls, via
  crafted LIVE SELECT s…
severity: medium
cvss: 5.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-863
published: '2025-09-26'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T10:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11060'
references:
  - url: 'https://access.redhat.com/security/cve/CVE-2025-11060'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2394708'
    label: secalert@redhat.com
  - url: 'https://github.com/surrealdb/surrealdb'
    label: secalert@redhat.com
  - url: >-
      https://github.com/surrealdb/surrealdb/commit/d81169a06b89f0c588134ddf2d62eeb8d5e8fd0c
    label: secalert@redhat.com
  - url: 'https://github.com/surrealdb/surrealdb/pull/6247'
    label: secalert@redhat.com
  - url: >-
      https://github.com/surrealdb/surrealdb/security/advisories/GHSA-7vm2-j586-vcvc
    label: secalert@redhat.com
  - url: 'https://surrealdb.com/docs/surrealql/statements/live'
    label: secalert@redhat.com
tags:
  - nvd
epss: 0.0032
epssPercentile: 0.22923
ingestedAt: '2026-10-09T12:53:27.522Z'
---

## Overview

A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or guest users to observe unauthorized records within the same table, bypassing access controls, via crafted LIVE SELECT subscriptions when other users alter or delete records.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
