HIGHVulnerability
Verified
Global

NVD HIGH: CVE-2026-102876 — SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construc...

·Source: NIST NVD

Updated:

Executive Summary

SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, cr

Analysis

SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries. CVSS Score: 8.1. Published: 2026-09-29T20:17:18.230.

Indicators of Compromise (1)

CVE (1)
CVE-2026-102876
Source Attribution

Originally published by NIST NVD on Sep 29, 2026. Verified by: NIST.

Related Threats