Executive brief
SurrealDB is a database management system that uses PERMISSIONS clauses to enforce fine-grained access controls on table operations. A logic flaw allows users with permission to perform a guarded operation (such as updating a table) to trigger unintended writes to other tables they do not have permission to access by embedding data-modification statements within permission evaluation logic. This bypasses intended access controls and can corrupt or modify data that should be restricted.
Technical details
This is an authorization bypass (CWE-863) caused by permission evaluation disabling permission enforcement to prevent infinite recursion. However, data-modifying statements (CREATE, UPDATE, DELETE, RELATE, INSERT, UPSERT) embedded within a PERMISSIONS ... WHERE clause execute with enforcement still disabled, allowing a low-privileged user to write to protected tables. The vulnerability affects PERMISSIONS clauses containing writes; FULL, NONE, and read-only clauses are unaffected. The clause evaluates once per matched record, enabling a single statement to cause multiple unintended writes and trigger cascading events or data corruption. The attack requires low-privilege database access but does not allow cross-database/namespace escape or root-level actions. SurrealDB 3.2.0 and later mitigate this by rejecting definitions of writable PERMISSIONS clauses and blocking writes during clause evaluation at runtime.
Affected products
- SurrealDB SurrealDB < 3.2.0
Timeline
- 2026-07-02: disclosed
- 2026-09-04: advisory
- 2026: patched: SurrealDB 3.2.0 and later