Junglewise Threat Intelligence

CVE-2026-54698: Hasura GraphQL Engine row-level authorization bypass in computed fields

CVE-2026-54698 · Severity: info · CVSS 7.7 · Published 2026-07-07

Executive brief

Hasura GraphQL Engine, a tool used to connect databases to applications via APIs, contains a security flaw in how it handles data access permissions. An authorized user could potentially bypass row-level security restrictions to discover sensitive information they are not supposed to see. By using specific search queries as a 'guessing' tool, an attacker could systematically reveal hidden data values, potentially leading to a breach of confidential records.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Hasura GraphQL Engine where row-level permissions are not properly applied to 'where' clauses on table computed fields returning 'SETOF some_table'. While the system prevents direct retrieval of unauthorized rows, an attacker with existing low-level access can use boolean predicates (such as 'like' on strings) within the 'where' clause as an oracle. This allows for efficient brute-forcing of sensitive values that should be filtered by the role's row-level permissions. The fix, available in versions 2.49.2 and 2.45.5, ensures that the returned table's row-level select filters are correctly applied to the computed-field boolean-expression path.

Affected products

  • Hasura graphql-engine >= 2.45.0, < 2.45.5; >= 2.46.0, < 2.49.2

Timeline

  • 2026-06-11: patched: Version 2.49.2 released
  • 2026-06-12: patched: Version 2.45.5 released
  • 2026-06-29: advisory: GitHub Security Advisory published
  • 2026-07-07: disclosed: CVE published to NVD

References