CVE-2024-58356

LOW

SurrealDB before 2.1.4 Permission Bypass via DEFINE TABLE OVERWRITE

Title source: cna
STIX 2.1

Description

SurrealDB before 2.1.4 silently fails to overwrite table definitions when the DEFINE TABLE ... OVERWRITE clause is used on tables defined with TYPE RELATION. Because table definitions include the PERMISSIONS clause, an attempt to tighten a table's permissions via OVERWRITE does not take effect, and the administrator may incorrectly believe the change was applied. As a result, a client authorized to run queries may continue to access data in that table that the updated (but unapplied) permissions were intended to restrict.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-27vq-hv74-7cqp)
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-27vq-hv74-7cqp
Third Party Advisory third-party-advisory
VulnCheck Advisory: SurrealDB before 2.1.4 Permission Bypass via DEFINE TABLE OVERWRITE
https://www.vulncheck.com/advisories/surrealdb-before-permission-bypass-via-define-table-overwrite

Scores

CVSS v4 2.3
EPSS 0.0027
EPSS Percentile 18.3%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-276
Status published
Products (2)
surrealdb/surrealdb < 2.1.4
surrealdb/surrealdb 2.1.4
Published Jul 18, 2026
Tracked Since Jul 18, 2026