Executive brief
SurrealDB is a multi-model cloud database. In affected versions, a security flaw allows unauthenticated users to create new namespaces and databases without permission. While attackers cannot access existing data, they can clutter the system with unauthorized resources or potentially exhaust storage capacity, impacting operational costs and management.
Technical details
A missing authorization check (CWE-862) exists in the SurrealDB RPC 'use' method, Datastore::process_use, and the SurrealQL executor. By design, the USE statement in SurrealDB automatically creates a target namespace or database if it does not exist; however, versions prior to 3.1.0 fail to verify if the caller possesses DEFINE NAMESPACE or DEFINE DATABASE permissions before performing this implicit creation. An unauthenticated remote attacker can exploit this to create arbitrary resources or recreate dropped namespaces using stale tokens. This can lead to storage exhaustion in the catalog, though it does not grant access to existing data or allow privilege escalation within existing namespaces. The issue is resolved in version 3.1.0.
Affected products
- SurrealDB SurrealDB < 3.1.0
Timeline
- 2026-05-27: advisory: Vendor GHSA published
- 2026-07-20: disclosed: CVE published to NVD