Executive brief
SurrealDB is a multi-model database platform used for data storage and management. A permissions bypass flaw in versions before 3.2.0 allows authenticated users with limited access to write to tables they shouldn't have permission to access by embedding data-modifying statements in PERMISSIONS clauses. An attacker could corrupt data across multiple records in a single operation, bypassing table-level access controls.
Technical details
The vulnerability exists in SurrealDB's permission evaluation mechanism (CWE-863: Incorrect Authorization). PERMISSIONS clauses are evaluated with enforcement disabled to prevent recursion into permission checks, but this also allows data-modifying SQL statements (CREATE, UPDATE, DELETE, RELATE, INSERT, UPSERT) embedded in the clause to execute without permission validation. An authenticated attacker with permission to trigger a guarded operation can exploit this by crafting a malicious permission clause that performs unauthorized writes to restricted tables. Since the clause evaluates once per matched record, a single statement can trigger multiple unauthorized writes. The fix (released in version 3.2.0) enforces read-only permission clauses by rejecting any writes in their definitions and blocking all write attempts during clause evaluation, including through called functions.
Affected products
- SurrealDB SurrealDB < 3.2.0
Timeline
- 2026-07-02: disclosed
- 2026-07-20: patched: Version 3.2.0 released