OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102876

HIGH · CVSS 8.1 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

SurrealDB versions prior to 3.3.0 are vulnerable to an authorization bypass due to improper session construction, allowing attackers to exploit the system by authenticating as a user from one tenant while accessing another tenant's namespace and database. This vulnerability enables unauthorized reading, creation, and modification of records across tenant boundaries, posing a significant risk to data integrity and confidentiality. Organizations using SurrealDB should prioritize patching this vulnerability to safeguard against potential data breaches and unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102876
Severity
HIGH
CVSS
8.1
EPSS
0.27%

Original NVD Description

SurrealDB before 3.3.0 contains an authorization bypass in HTTP session construction where check_auth() verifies credentials against Surreal-Auth-NS and Surreal-Auth-DB headers but constructs sessions using Surreal-NS and Surreal-DB headers without validating access permissions. Attackers can authenticate as a user from one tenant while selecting another tenant's namespace and database to read, create, and modify records across tenant boundaries.