PT-2026-61551 · Surrealdb · Surrealdb
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
SurrealDB versions prior to 3.2.0
Description
Custom API routes fail to validate namespace and database scope, which allows authenticated users to invoke endpoints across different namespaces or databases. An attacker with valid credentials for any namespace or database can access custom API endpoints belonging to other tenants by specifying the target scope within the URL path. This can lead to the unauthorized reading of sensitive data or the triggering of unintended operations.
Recommendations
Update SurrealDB to version 3.2.0 or later.
Fix
IDOR
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Surrealdb