PT-2026-102892 · Surrealdb · Surrealdb

·

CVE-2026-102876

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102876

Affected Products

Surrealdb