PT-2026-61549 · Surrealdb · Surrealdb

·

CVE-2026-63733

·

Published

2026-07-20

·

Updated

2026-09-05

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SurrealDB versions prior to 3.2.0
Description A permissions bypass exists where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers who have permission to perform a guarded operation can write to tables for which they lack authorization by embedding CREATE, UPDATE, DELETE, or UPSERT statements in the PERMISSIONS clause, leading to unintended writes and data corruption.
Recommendations Update to version 3.2.0 or later.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-63733
GHSA-66R2-5GWJ-GXM2
GHSA-6G69-7XMF-H2X7

Affected Products

Surrealdb