{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/surrealdb--3.3.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:surrealdb:surrealdb:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-102876"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SurrealDB (\u003c 3.3.0)"],"_cs_severities":["high"],"_cs_tags":["authorization-bypass","cve-2026-102876","surrealdb"],"_cs_type":"advisory","_cs_vendors":["SurrealDB"],"content_html":"\u003cp\u003eSurrealDB versions prior to 3.3.0 are susceptible to an authorization bypass vulnerability within the HTTP session construction logic. The vulnerability originates from a flaw in the \u003ccode\u003echeck_auth()\u003c/code\u003e process, which verifies user credentials against the \u003ccode\u003eSurreal-Auth-NS\u003c/code\u003e and \u003ccode\u003eSurreal-Auth-DB\u003c/code\u003e headers but fails to validate these credentials against the requested target namespace and database defined in the \u003ccode\u003eSurreal-NS\u003c/code\u003e and \u003ccode\u003eSurreal-DB\u003c/code\u003e headers.\u003c/p\u003e\n\u003cp\u003eThis logic gap permits an authenticated user to craft HTTP requests that authenticate them successfully against their own tenant space, while simultaneously directing the application to perform read, create, or modify operations on the database and namespace of an entirely different tenant. Because the application trusts the session namespace/database headers without secondary access control verification, this flaw facilitates horizontal and potentially vertical privilege escalation across tenant boundaries. Defenders should prioritize updating to version 3.3.0 to enforce strict header-to-credential validation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to bypass tenant isolation controls, resulting in unauthorized access to sensitive data and the ability to manipulate records across the target organization's infrastructure. This vulnerability poses a high risk to multi-tenant environments where data integrity and confidentiality between distinct tenants are critical security requirements.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade SurrealDB to version 3.3.0 or later immediately to patch CVE-2026-102876.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation on HTTP headers \u003ccode\u003eSurreal-NS\u003c/code\u003e and \u003ccode\u003eSurreal-DB\u003c/code\u003e at the network gateway or application firewall layer to ensure they correspond to the authenticated user's authorized scope.\u003c/li\u003e\n\u003cli\u003eAudit access logs for anomalous cross-tenant activity originating from a single authenticated user session.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-29T20:29:56Z","date_published":"2026-09-29T20:29:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-surrealdb-auth-bypass/","summary":"SurrealDB versions before 3.3.0 contain an authorization bypass vulnerability where improper namespace and database header validation allows authenticated users to perform unauthorized cross-tenant data operations.","title":"Authorization Bypass in SurrealDB HTTP Session Construction","url":"https://feed.craftedsignal.io/briefs/2026-09-surrealdb-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - SurrealDB (\u003c 3.3.0)","version":"https://jsonfeed.org/version/1.1"}