{"id":"CVE-2026-49997","aliases":["GHSA-whwg-vh4f-pmmf"],"url":"https://o3.security/vulnerability/CVE-2026-49997","summary":"SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted","details":"SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Document::purge_edges in surrealdb/core/src/doc/delete.rs automatically removed graph edge records with permissions disabled through opt.clone().with_perms(false) when a connected node was deleted, bypassing the edge table's PERMISSIONS FOR delete and PERMISSIONS FOR select clauses. This issue is fixed in version 3.1.0.","published":"2026-07-15T16:14:03.602Z","modified":"2026-08-12T03:51:08.780082564Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"surrealdb","fixedVersion":"3.1.0"}],"fix":{"url":"https://github.com/surrealdb/surrealdb/commit/500f4060349580b9cbb9c07b8112a487551c4616","label":"surrealdb/surrealdb@500f406"},"references":[{"type":"WEB","url":"https://github.com/surrealdb/surrealdb/releases/tag/v3.1.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49997.json"},{"type":"ADVISORY","url":"https://github.com/surrealdb/surrealdb/security/advisories/GHSA-whwg-vh4f-pmmf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49997"},{"type":"FIX","url":"https://github.com/surrealdb/surrealdb/commit/500f4060349580b9cbb9c07b8112a487551c4616"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:08.780082564Z"}}