HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-45830

CVSS 8.8v4.0pub. 2026-06-12upd. 2026-06-30

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Trychroma Chromadb

    APP
    Trychroma
    0.4.17 – 1.5.9
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-45833CRITICAL9.4PL ✓same product

ChromaDB: code injection przez złośliwe repozytorium modelu (RCE)

CVE-2026-45831HIGH8.8same product

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python p...

CVE-2026-45832HIGH8.8same product

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the au...