Skip to content
ChromaGHSA-2wm9-hf6c-p5cr

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

High8.8CVE-2026-45830 · Published Jun 12, 2026 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
chromadb
PyPI
>= 0.4.17, <= 1.5.9No fix yet
Details and references

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-266, CWE-639
Also known as
CVE-2026-45830, PYSEC-2026-3813

More Chroma advisories

All Chroma
DateAdvisory
Jun 12ChromaDB has a code injection vulnerability
CVE-2026-45833Criticalno fix yet
Jun 12ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
CVE-2026-45831High8.8no fix yet
May 18ChromaDB Python project has a pre-authentication code injection vulnerability
CVE-2026-45829Criticalno fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.