A vulnerability, which was classified as critical, was found in SurrealDB up to 3.0.x. Affected by this vulnerability is an unknown functionality of the component Record ID. Executing a manipulation of the argument body can lead to authorization bypass.
This vulnerability appears as CVE-2026-63745. The attack may be performed from remote. There is no available exploit.