Junglewise Threat Intelligence

CVE-2023-54366: SurrealDB insecure default table permissions

CVE-2023-54366 · Severity: high · CVSS 8.8 · Published 2026-07-18

Technologies: surrealdb (crates.io). Vendors: PyPI, crates.io, SurrealDB.

Executive brief

SurrealDB is a distributed document-graph database used as a backend for applications requiring data storage and retrieval. When tables are defined without explicit permissions, the database defaults to granting full access (SELECT, CREATE, UPDATE, DELETE) to all authorized clients. This is particularly dangerous for publicly exposed instances allowing guest access, where unauthenticated remote users could read, modify, or delete any unprotected data stored in tables without explicit permission rules.

Technical details

SurrealDB had a default permissions vulnerability (CWE-276: Incorrect Default Permissions) where tables created without an explicit PERMISSIONS clause received FULL access for SELECT, CREATE, UPDATE, and DELETE operations instead of restrictive NONE permissions. The vulnerability affects the table definition mechanism itself; any table defined before patching lacks granular access control. Attack vector is network when instances expose HTTP REST API or WebSocket APIs with guest access enabled, allowing unauthenticated or low-privileged users to perform unrestricted CRUD operations on affected tables. Patched versions (1.0.1+, 1.1.0-beta.1+) change default permissions to NONE and ensure INFO FOR DB displays all permissions explicitly. Workarounds for unpatched versions involve explicitly specifying PERMISSIONS NONE or role-based rules during table definition.

Affected products

  • SurrealDB SurrealDB < 1.0.1

Timeline

  • 2023-12-15: disclosed
  • 2023-12-15: patched: Version 1.0.1 released with patch; 1.1.0-beta.1 and later also include fix

References

Related threats