CVE-2026-102876
Deferred Deferred - Pending Action

Authorization Bypass in SurrealDB HTTP Sessions

Vulnerability report for CVE-2026-102876, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
surrealdb surrealdb to 3.3.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SurrealDB before 3.3.0 has an authorization bypass where authentication is verified using Surreal-Auth-NS and Surreal-Auth-DB headers but sessions are constructed using Surreal-NS and Surreal-DB headers without proper permission checks. This allows attackers to authenticate as one tenant while accessing another tenant's data.

Detection Guidance

To detect this vulnerability, check SurrealDB server versions prior to 3.3.0. Use commands like 'surreal version' or inspect package managers for outdated installations. Monitor HTTP headers Surreal-NS and Surreal-DB for cross-tenant access attempts.

Impact Analysis

Attackers with valid credentials for one tenant could read, modify, or delete data in another tenant's namespace or database. This bypasses tenant isolation, potentially exposing sensitive data across tenants. Only root users or single-tenant deployments are unaffected.

Compliance Impact

This vulnerability could lead to unauthorized data access across tenants, violating data isolation requirements in GDPR and HIPAA. It may result in non-compliance due to potential exposure of personal or health data to unauthorized parties.

Mitigation Strategies

Upgrade SurrealDB to version 3.3.0 or later immediately. If upgrading is not possible, isolate tenants into separate deployments or avoid PERMISSIONS FULL configurations to reduce exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102876. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart