PT-2026-61549 · Surrealdb · Surrealdb
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SurrealDB versions prior to 3.2.0
Description
A permissions bypass exists where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers who have permission to perform a guarded operation can write to tables for which they lack authorization by embedding CREATE, UPDATE, DELETE, or UPSERT statements in the PERMISSIONS clause, leading to unintended writes and data corruption.
Recommendations
Update to version 3.2.0 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Surrealdb