8.6

CVE-2026-102876

SurrealDB before 3.3.0 Cross-Tenant Access via Headers

SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellersurrealdb
≫
Produkt surrealdb
Default Statusunaffected
Version 0
Version < 3.3.0
Status affected
Version 3.3.0
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.174
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
disclosure@vulncheck.com 8.6 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
disclosure@vulncheck.com 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

https://github.com/surrealdb/surrealdb
https://github.com/surrealdb/surrealdb/security/advisories/GHSA-vx2p-7hhm-wv62
https://github.com/surrealdb/surrealdb/commit/5000e233b4a8b96689c82715c172061dcf711d31
https://github.com/surrealdb/surrealdb/blob/v3.2.4/surrealdb/server/src/ntw/auth.rs
https://github.com/surrealdb/surrealdb/releases/tag/v3.3.0
https://www.vulncheck.com/advisories/surrealdb-before-3.3.0-cross-tenant-access-via-headers