Authorization Bypass in SurrealDB Results in Cross-Tenant Access
CVE-2026-102876

8.6HIGH

Key Information:

Vendor

Surrealdb

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102876?

SurrealDB versions prior to 3.3.0 exhibit a significant vulnerability where the authorization process is compromised during HTTP session construction. Specifically, the function check_auth() checks user credentials against the Surreal-Auth-NS and Surreal-Auth-DB headers; however, it constructs sessions using the Surreal-NS and Surreal-DB headers without proper access permission validation. Consequently, an attacker could potentially impersonate a user from one tenant while accessing another tenant's namespace and database, enabling unauthorized reading, creation, and modification of records across tenant boundaries. This flaw emphasizes the need for stringent session validation to protect multi-tenant architectures.

Affected Version(s)

surrealdb 0 < 3.3.0

surrealdb 3.3.0

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alpesh Bhagwatkar
.