HIGH
SurrealDB before 2.0.4 Improper Authorization via SELECT Permissions
Published Jul 18, 2026
7.1
HIGHCVSS 4.0
EPSS 0.36%
Description
SurrealDB versions before 2.0.4 fail to properly enforce field permissions during SELECT, UPDATE, and DELETE operations, allowing authorized users to access unauthorized field values through various query techniques. Attackers can exploit SELECT VALUE operations, field aliasing, function arguments, WHERE clause filtering, RETURN BEFORE clauses, and SET clause references to leak protected field contents despite lacking SELECT permissions.
Affected products
-
- Version 0StatusaffectedConstraints<2.0.4
- Version 2.0.4StatusunaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (15)
- https://github.com/advisories/GHSA-9722-9j67-vjcr Advisory
- https://github.com/surrealdb/surrealdb/commit/439ab99e15314ec5cf87047bf58246db646e3f8c
- https://github.com/surrealdb/surrealdb/commit/c382fa158dc84b329328606f663efe574f102a7d
- https://github.com/surrealdb/surrealdb/commit/e75e7736b3a028c4b6a4a4bdf00791d76f77e339
- https://github.com/surrealdb/surrealdb/issues/2161
- https://github.com/surrealdb/surrealdb/issues/3924
- https://github.com/surrealdb/surrealdb/pull/4785
- https://github.com/surrealdb/surrealdb/pull/4800
- https://github.com/surrealdb/surrealdb/pull/4873
- https://github.com/surrealdb/surrealdb/security/advisories/GHSA-9722-9j67-vjcr vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-58367
- https://surrealdb.com/docs/surrealdb/security/summary#permissions
- https://surrealdb.com/docs/surrealql/statements/define/field#setting-permissions-on-fields
- https://surrealdb.com/docs/surrealql/statements/define/table#defining-permissions
- https://www.vulncheck.com/advisories/surrealdb-before-improper-authorization-via-select-permissions third-party-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 18, 2026
Updated Jul 28, 2026
Reserved Jul 18, 2026
Link CVE-2024-58367
CISA Vulnrichment
GHSA-9722-9J67-VJCR Updated Jul 21, 2026