Junglewise Threat Intelligence

CVE-2026-63733: SurrealDB permissions bypass via data-modifying statements in PERMISSIONS clause

CVE-2026-63733 · Severity: medium · CVSS 4.3 · Published 2026-07-20

Technologies: surrealdb-core (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB is a database management system that uses PERMISSIONS clauses to enforce fine-grained access controls on table operations. A logic flaw allows users with permission to perform a guarded operation (such as updating a table) to trigger unintended writes to other tables they do not have permission to access by embedding data-modification statements within permission evaluation logic. This bypasses intended access controls and can corrupt or modify data that should be restricted.

Technical details

This is an authorization bypass (CWE-863) caused by permission evaluation disabling permission enforcement to prevent infinite recursion. However, data-modifying statements (CREATE, UPDATE, DELETE, RELATE, INSERT, UPSERT) embedded within a PERMISSIONS ... WHERE clause execute with enforcement still disabled, allowing a low-privileged user to write to protected tables. The vulnerability affects PERMISSIONS clauses containing writes; FULL, NONE, and read-only clauses are unaffected. The clause evaluates once per matched record, enabling a single statement to cause multiple unintended writes and trigger cascading events or data corruption. The attack requires low-privilege database access but does not allow cross-database/namespace escape or root-level actions. SurrealDB 3.2.0 and later mitigate this by rejecting definitions of writable PERMISSIONS clauses and blocking writes during clause evaluation at runtime.

Affected products

  • SurrealDB SurrealDB < 3.2.0

Timeline

  • 2026-07-02: disclosed
  • 2026-09-04: advisory
  • 2026: patched: SurrealDB 3.2.0 and later

References

Related threats