CVE Explorer
CVE-2026-54698
Hasura is an open-source product that provides users GraphQL or REST APIs. Prior to 2.49.2 and 2.45.5, a user can use a where clause on a table computed field (returning SETOF some_table) to infer row values that ought to be filtered for their role based on some_table's row-level permissions. While such rows cannot be returned directly, like predicates on strings for instance allow values to be brute forced efficiently with the where clause as an oracle. This issue is fixed in versions 2.49.2 an
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"graphql-engine","vendor":"hasura","versions":[{"status":"affected","version":">= 2.46.0, < 2.49.2"},{"status":"affected","version":">= 2.45.0, < 2.45.5"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:08f952aeb8296a1175202634decfaf325dbbe2089c2c87e358a0e827d9a6bdf2 · sha256:78053a9b85bf37e5… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:08f952aeb8296a1175202634decfaf325dbbe2089c2c87e358a0e827d9a6bdf2 · sha256:78053a9b85bf37e5… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:08f952aeb8296a1175202634decfaf325dbbe2089c2c87e358a0e827d9a6bdf2 · sha256:78053a9b85bf37e5… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"https://github.com/hasura/graphql-engine/security/advisories/GHSA-r27x-gc74-qmxh","tags":["x_refsource_CONFIRM"],"url":"https://github.com/hasura/graphql-engine/security/advisories/GHSA-r27x-gc74-qmxh"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:08f952aeb8296a1175202634decfaf325dbbe2089c2c87e358a0e827d9a6bdf2 · sha256:78053a9b85bf37e5… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.