CVE-2026-49997: SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::purge_edges in surrealdb/core/src/doc/delete.rs automat
SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::purge_edges in surrealdb/core/src/doc/delete.rs automatically removed graph edge records with permissions disabled through opt.clone().with_perms(false) when a connected node was deleted, bypassing the edge table's PERMISSIONS FOR delete and PERMISSIONS FOR select clauses. This issue is fixed in version 3.1.0.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-49997
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-499970.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-49997 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for SurrealDB is a
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-63763: SurrealDB before 2.5.0 and before 3.0.0-beta.3 contains a confused deputy privilege escalation…nvd · 2026-07-20
- mediumCVE-2026-63762: SurrealDB before v2.6.1 (and before v3.0.0-beta.3) contains a denial of service vulnerability …nvd · 2026-07-20
- mediumCVE-2026-63761: SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is co…nvd · 2026-07-20
- highCVE-2026-63760: SurrealDB before 3.1.0 fails to enforce the configured recursion depth limit in the value and …nvd · 2026-07-20
- mediumCVE-2026-63759: SurrealDB before 3.1.0 fails to enforce recursion depth limits in the type/kind parser when pr…nvd · 2026-07-20
- mediumCVE-2026-63758: SurrealDB versions before 3.1.0 contain an authorization bypass vulnerability in the KILL stat…nvd · 2026-07-20
More from NVD Recent CVEs
- unknownCVE-2026-70474: Flowise is a drag-and-drop user interface for building customized large language model (LLM) f…2026-08-04
- unknownCVE-2026-70473: Flowise is a drag-and-drop user interface for building customized large language model (LLM) f…2026-08-04
- unknownCVE-2026-70472: Flowise is a drag & drop user interface to build a customized large language model flow. Prior…2026-08-04
- unknownCVE-2026-70471: Flowise is a drag-and-drop user interface for building customized large language model (LLM) f…2026-08-04
- mediumCVE-2026-69704: Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate databas…2026-08-04