CVE-2026-63733

MEDIUM

SurrealDB before 3.2.0 Permissions Bypass via PERMISSIONS Clause

Title source: cna
STIX 2.1

Description

SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMISSIONS clauses execute with enforcement disabled. Attackers with permission to perform a guarded operation can write to tables they lack permission for by embedding CREATE, UPDATE, DELETE, or UPSERT statements in the PERMISSIONS clause, causing unintended writes and data corruption.

References (2)

Core 2
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-66r2-5gwj-gxm2)
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-66r2-5gwj-gxm2
Third Party Advisory third-party-advisory
VulnCheck Advisory: SurrealDB before 3.2.0 Permissions Bypass via PERMISSIONS Clause
https://www.vulncheck.com/advisories/surrealdb-before-permissions-bypass-via-permissions-clause

Scores

CVSS v3 4.3
EPSS 0.0020
EPSS Percentile 10.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
surrealdb/surrealdb < 3.2.0 (2 CPE variants)
surrealdb/surrealdb 3.2.0
Published Jul 20, 2026
Tracked Since Jul 20, 2026