8.6
CVE-2026-102876
- EPSS 0.27%
- Veröffentlicht 29.09.2026 20:01:06
- Zuletzt bearbeitet 02.10.2026 13:17:31
- Erkennungen
SurrealDB before 3.3.0 Cross-Tenant Access via Headers
SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellersurrealdb
≫
Produkt
surrealdb
Default Statusunaffected
Version
0
Version <
3.3.0
Status
affected
Version
3.3.0
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.174 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.6 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 8.1 | 2.8 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://github.com/surrealdb/surrealdb
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-vx2p-7hhm-wv62
https://github.com/surrealdb/surrealdb/commit/5000e233b4a8b96689c82715c172061dcf711d31
https://github.com/surrealdb/surrealdb/blob/v3.2.4/surrealdb/server/src/ntw/auth.rs
https://github.com/surrealdb/surrealdb/releases/tag/v3.3.0
https://www.vulncheck.com/advisories/surrealdb-before-3.3.0-cross-tenant-access-via-headers