Description
SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server.
Published: 2026-07-18
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

SurrealDB versions earlier than 2.1.0 contain an error handling flaw in the role conversion process. Privileged owner users can assign users to roles that do not exist. When such a user signs in, the server triggers an uncaught panic that crashes the database, causing a denial of service. The impact is loss of availability; an attacker who can create or modify role assignments can effectively bring the database offline. Based on the description, it is inferred that the attack vector is authenticated and remote.

Affected Systems

All builds of SurrealDB prior to 2.1.0 are affected, regardless of operating system or deployment environment. The vulnerability exists in the SurrealDB engine's role management component, and any instance running an unpatched version is at risk.

Risk and Exploitability

The CVSS base score of 6.9 indicates a moderate severity vulnerability, while the EPSS score of less than 1% suggests that it is not currently a high‑volume target. The vulnerability is not listed in the CISA KEV catalog. Because it requires an owner‑level user to create a user with an invalid role and a subsequent login to trigger the crash, the attack vector is considered authenticated and remote, but it can be performed from an externally accessible endpoint if a privileged account is present; this inference is based on the description.

Generated by OpenCVE AI on July 30, 2026 at 23:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SurrealDB to version 2.1.0 or later to apply the vendor’s fix that validates role existence during assignment.
  • Remove any users that have been assigned to non‑existent roles and revoke those role assignments from existing accounts.
  • Until the upgrade is completed, temporarily disable the ability for owner users to create or modify users, or configure the database to reject role assignments that reference undefined roles.

Generated by OpenCVE AI on July 30, 2026 at 23:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Surrealdb
Surrealdb surrealdb
Vendors & Products Surrealdb
Surrealdb surrealdb

Mon, 20 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Attackers can trigger an uncaught panic by signing in with a user assigned an invalid role, crashing the server.
Title SurrealDB before 2.1.0 Denial of Service via Nonexistent Role
Weaknesses CWE-248
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Surrealdb Surrealdb
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-07-28T01:47:47.875Z

Reserved: 2026-06-08T15:20:35.497Z

Link: CVE-2024-58358

cve-icon Vulnrichment

Updated: 2026-07-20T13:40:20.598Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:15:06Z

Weaknesses