Junglewise Threat Intelligence

SurrealDB incorrect authorization in table permission checks

Severity: medium · CVSS 6.5 · Published 2026-07-01

Technologies: surrealdb (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

A security flaw in SurrealDB allows authenticated users to bypass table-level permission restrictions and read sensitive data they should not have access to. By using specific database queries, an attacker can trick the system into revealing record contents before the security checks are applied. This could lead to the unauthorized exposure of all data within the specific database the user is logged into.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in SurrealDB where user-supplied clauses (such as WHERE, SET, MERGE, CONTENT, and PATCH) are evaluated against record data before the 'PERMISSIONS FOR SELECT WHERE' check is enforced. An authenticated attacker can use side-effecting expressions, such as scripting functions or the SurrealQL THROW statement, to exfiltrate record contents. While scripting functions facilitate the attack, timing-based side-channel extraction is also possible. The vulnerability is limited to the attacker's current database and does not cross namespace boundaries. The issue is fixed in version 3.1.0 by ensuring permission checks occur before expression evaluation.

Affected products

  • SurrealDB surrealdb < 3.1.0

Timeline

  • 2026-05-27: disclosed
  • 2026-07-01: advisory
  • 2026-07-01: patched: Version 3.1.0 released

References

Related threats