ChromaGHSA-2wm9-hf6c-p5cr
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
High8.8CVE-2026-45830 · Published Jun 12, 2026 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| chromadb PyPI | >= 0.4.17, <= 1.5.9 | No fix yet |
Details and references
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-266, CWE-639
- Also known as
- CVE-2026-45830, PYSEC-2026-3813
- nvd.nist.gov/vuln/detail/CVE-2026-45830
- github.com/chroma-core/chroma/issues/7588
- github.com/chroma-core/chroma/pull/7602
- access.redhat.com/security/cve/CVE-2026-45830
- bugzilla.redhat.com/show_bug.cgi?id=2488408
- github.com/chroma-core/chroma
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45830.json
- www.hiddenlayer.com/sai-security-advisory/2026-06-chromadb
More Chroma advisories
All Chroma| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 12 | ChromaDB has a code injection vulnerability CVE-2026-45833Criticalno fix yet | Critical | No fix yet |
| Jun 12 | ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to CVE-2026-45831High8.8no fix yet | High8.8 | No fix yet |
| May 18 | ChromaDB Python project has a pre-authentication code injection vulnerability CVE-2026-45829Criticalno fix yet | Critical | No fix yet |