Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.7
CVE-2023-54366: SurrealDB before 1.0.1 allows unauthorized database access
CVE-2023-54366
Summary
SurrealDB versions prior to 1.0.1 have a default permission setting that allows anyone with database access to perform various operations on tables without explicit permission. This means attackers or unauthenticated users can make changes to your data. To protect your SurrealDB, update to version 1.0.1 or later.
Original title
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database...
Original description
SurrealDB before 1.0.1 sets default table permissions to FULL instead of NONE, allowing SELECT, CREATE, UPDATE, and DELETE operations on tables without explicit permissions. Attackers with database access or unauthenticated users on publicly exposed instances can perform unrestricted operations on unprotected tables within their authorization scope.
nvd CVSS3.1
8.8
nvd CVSS4.0
8.7
Vulnerability type
CWE-276
Incorrect Default Permissions
Published: 18 Jul 2026 · Updated: 19 Jul 2026 · First seen: 18 Jul 2026