Back

MEDIUM

SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch

Published Jul 20, 2026

Description

SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allows authenticated users to read protected fields. Attackers can use UPDATE PATCH with an empty from pointer in copy or move operations to duplicate all record fields, including those restricted by field-level SELECT permissions, into attacker-chosen destination fields.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 20, 2026
Updated Jul 28, 2026
Reserved Jul 18, 2026
CISA Vulnrichment
Updated Jul 20, 2026
NVD
Status Analyzed
Modified Jul 22, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-FPXG-5XMV-922M