Authorization Bypass in SurrealDB Results in Cross-Tenant Access
CVE-2026-102876
What is CVE-2026-102876?
SurrealDB versions prior to 3.3.0 exhibit a significant vulnerability where the authorization process is compromised during HTTP session construction. Specifically, the function check_auth() checks user credentials against the Surreal-Auth-NS and Surreal-Auth-DB headers; however, it constructs sessions using the Surreal-NS and Surreal-DB headers without proper access permission validation. Consequently, an attacker could potentially impersonate a user from one tenant while accessing another tenant's namespace and database, enabling unauthorized reading, creation, and modification of records across tenant boundaries. This flaw emphasizes the need for stringent session validation to protect multi-tenant architectures.
Affected Version(s)
surrealdb 0 < 3.3.0
surrealdb 3.3.0
