---
id: CVE-2026-63752
title: SurrealDB before 3.1.0 RELATE Statement Record Overwrite
summary: >-
  SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the
  RELATE statement that allows authenticated users with CREATE permission to
  overwrite existing edge records without UPDATE permission. Attackers can issue
  a RELA…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-285
vendor: surrealdb
product: surrealdb
affected:
  - surrealdb < 3.1.0
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-20T19:23:27.802373Z'
published: '2026-07-20'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T15:23:49.220Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2026-63752'
references:
  - url: >-
      https://github.com/surrealdb/surrealdb/security/advisories/GHSA-f82j-v89j-mf86
    label: GitHub Security Advisory (GHSA-f82j-v89j-mf86)
  - url: >-
      https://www.vulncheck.com/advisories/surrealdb-before-relate-statement-record-overwrite
    label: >-
      VulnCheck Advisory: SurrealDB before 3.1.0 RELATE Statement Record
      Overwrite
tags:
  - cve.org
epss: 0.0028
epssPercentile: 0.18716
ingestedAt: '2026-10-08T16:52:14.792Z'
---

## Overview

SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated users with CREATE permission to overwrite existing edge records without UPDATE permission. Attackers can issue a RELATE statement with a SET id clause pointing to an existing edge id, causing the storage layer to silently overwrite the target record instead of rejecting the operation.

## Affected

- `surrealdb < 3.1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
