Junglewise Threat Intelligence

SurrealDB permissions bypass via PERMISSIONS clause

Severity: medium · CVSS 4.3 · Published 2026-07-20

Technologies: surrealdb (crates.io). Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB is a multi-model database platform used for data storage and management. A permissions bypass flaw in versions before 3.2.0 allows authenticated users with limited access to write to tables they shouldn't have permission to access by embedding data-modifying statements in PERMISSIONS clauses. An attacker could corrupt data across multiple records in a single operation, bypassing table-level access controls.

Technical details

The vulnerability exists in SurrealDB's permission evaluation mechanism (CWE-863: Incorrect Authorization). PERMISSIONS clauses are evaluated with enforcement disabled to prevent recursion into permission checks, but this also allows data-modifying SQL statements (CREATE, UPDATE, DELETE, RELATE, INSERT, UPSERT) embedded in the clause to execute without permission validation. An authenticated attacker with permission to trigger a guarded operation can exploit this by crafting a malicious permission clause that performs unauthorized writes to restricted tables. Since the clause evaluates once per matched record, a single statement can trigger multiple unauthorized writes. The fix (released in version 3.2.0) enforces read-only permission clauses by rejecting any writes in their definitions and blocking all write attempts during clause evaluation, including through called functions.

Affected products

  • SurrealDB SurrealDB < 3.2.0

Timeline

  • 2026-07-02: disclosed
  • 2026-07-20: patched: Version 3.2.0 released

References

Related threats