PT-2026-60936 · Surrealdb · Surrealdb

·

CVE-2023-54366

·

Published

2023-12-15

·

Updated

2026-07-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 1.0.1
Description Default table permissions are set to FULL instead of NONE, which allows SELECT, CREATE, UPDATE, and DELETE operations on tables that lack explicit permissions. This allows attackers with database access or unauthenticated users on publicly exposed instances to perform unrestricted operations on unprotected tables within their authorization scope.
Recommendations Update SurrealDB to version 1.0.1 or later.

Exploit

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-54366
GHSA-M8PP-QC66-6PGP
GHSA-X5FR-7HHJ-34J3
PYSEC-2026-3718

Affected Products

Surrealdb