HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-45832

CVSS 8.8v4.0pub. 2026-06-12upd. 2026-06-30

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Trychroma Chromadb

    APP
    Trychroma
    0.5.0 – 1.5.9
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-45833CRITICAL9.4PL ✓same product

ChromaDB: code injection przez złośliwe repozytorium modelu (RCE)

CVE-2026-45830HIGH8.8same product

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authen...

CVE-2026-45831HIGH8.8same product

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python p...