A vulnerability was found in SurrealDB up to 2.6.0/3.0.0-beta.2. It has been declared as problematic. The impacted element is an unknown function of the component Scripting Engine. Executing a manipulation can lead to null pointer dereference.

This vulnerability is handled as CVE-2026-63762. The attack can be executed remotely. There is not any exploit available.