Junglewise Threat Intelligence

SurrealDB silent failure to overwrite table definition for relation types

Severity: medium · CVSS 6.3 · Published 2026-07-18

Technologies: surrealdb (crates.io), Surrealdb-Core. Vendors: SurrealDB, crates.io.

Executive brief

SurrealDB is a database management system used to store and manage structured data. When administrators attempt to update access permissions on tables defined with TYPE RELATION using the OVERWRITE clause, the database silently fails to apply the changes while indicating success, leaving more permissive access controls in place than intended. This allows authorized database users to access data they should no longer have permission to view.

Technical details

This is an incorrect default permissions vulnerability (CWE-276) affecting the DEFINE TABLE statement implementation in SurrealDB. The root cause is that the OVERWRITE clause fails to properly update table definitions when the table is defined with TYPE RELATION, specifically failing to apply changes to the PERMISSIONS clause within those definitions. An authenticated attacker with the ability to execute queries can exploit this by attempting to request a permission change via the DEFINE TABLE ... OVERWRITE command; while the system responds as if the change succeeded, it silently fails to apply the tighter permissions, allowing the attacker to continue accessing data they should no longer have authorization for. The vulnerability requires network access and authenticated database query execution privileges. The issue was patched in version 2.1.4 and later.

Affected products

  • SurrealDB surrealdb >= 2.0.0, < 2.1.4
  • SurrealDB surrealdb-core >= 2.0.0, < 2.1.4

Timeline

  • 2024-12-16: disclosed: Original advisory GHSA-27vq-hv74-7cqp published
  • 2026-07-18: advisory: Duplicate advisory GHSA-vmg6-53r4-jhpw published
  • 2026-09-04: other: Duplicate advisory GHSA-vmg6-53r4-jhpw withdrawn

References

Related threats