Authorization Bypass in SurrealDB HTTP Session Construction
SurrealDB versions before 3.3.0 contain an authorization bypass vulnerability where improper namespace and database header validation allows authenticated users to perform unauthorized cross-tenant data operations.
CVE search metadata
CVE search record: CVE-2026-102876. Severity: high. CVSS: 8.1. KEV: no. Product: SurrealDB (< 3.3.0). Brief: Authorization Bypass in SurrealDB HTTP Session Construction. Brief link: https://feed.craftedsignal.io/briefs/2026-09-surrealdb-auth-bypass/
SurrealDB versions prior to 3.3.0 are susceptible to an authorization bypass vulnerability within the HTTP session construction logic. The vulnerability originates from a flaw in the check_auth() process, which verifies user credentials against the Surreal-Auth-NS and Surreal-Auth-DB headers but fails to validate these credentials against the requested target namespace and database defined in the Surreal-NS and Surreal-DB headers.
This logic gap permits an authenticated user to craft HTTP requests that authenticate them successfully against their own tenant space, while simultaneously directing the application to perform read, create, or modify operations on the database and namespace of an entirely different tenant. Because the application trusts the session namespace/database headers without secondary access control verification, this flaw facilitates horizontal and potentially vertical privilege escalation across tenant boundaries. Defenders should prioritize updating to version 3.3.0 to enforce strict header-to-credential validation.
Impact
Successful exploitation allows an authenticated attacker to bypass tenant isolation controls, resulting in unauthorized access to sensitive data and the ability to manipulate records across the target organization's infrastructure. This vulnerability poses a high risk to multi-tenant environments where data integrity and confidentiality between distinct tenants are critical security requirements.
Recommendation
- Upgrade SurrealDB to version 3.3.0 or later immediately to patch CVE-2026-102876.
- Implement strict input validation on HTTP headers
Surreal-NSandSurreal-DBat the network gateway or application firewall layer to ensure they correspond to the authenticated user's authorized scope. - Audit access logs for anomalous cross-tenant activity originating from a single authenticated user session.
Immediate actions
Upgrade all SurrealDB instances to version 3.3.0 or later
Mitigations
Upgrade to version 3.3.0
CVE-2026-102876