Impact
SurrealDB versions earlier than 2.1.0 contain an error handling flaw in the role conversion process. Privileged owner users can assign users to roles that do not exist. When such a user signs in, the server triggers an uncaught panic that crashes the database, causing a denial of service. The impact is loss of availability; an attacker who can create or modify role assignments can effectively bring the database offline. Based on the description, it is inferred that the attack vector is authenticated and remote.
Affected Systems
All builds of SurrealDB prior to 2.1.0 are affected, regardless of operating system or deployment environment. The vulnerability exists in the SurrealDB engine's role management component, and any instance running an unpatched version is at risk.
Risk and Exploitability
The CVSS base score of 6.9 indicates a moderate severity vulnerability, while the EPSS score of less than 1% suggests that it is not currently a high‑volume target. The vulnerability is not listed in the CISA KEV catalog. Because it requires an owner‑level user to create a user with an invalid role and a subsequent login to trigger the crash, the attack vector is considered authenticated and remote, but it can be performed from an externally accessible endpoint if a privileged account is present; this inference is based on the description.
OpenCVE Enrichment