ChromaGHSA-xph7-9rjv-w5fr
Chroma: improper authorization
High8.8CVE-2026-45831 · Published Jun 12, 2026 · updated Sep 10, 2026
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| chromadb PyPI | >= 0.5.0, <= 1.5.9 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-863
- Also known as
- CVE-2026-45831, PYSEC-2026-3815
More Chroma advisories
All Chroma| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 12 | Chroma: insecure direct object reference | High8.8 | No fix yet |
| Jun 12 | ChromaDB has a code injection vulnerability | Critical | No fix yet |
| May 18 | ChromaDB Python project has a pre-authentication code injection vulnerability | Critical | No fix yet |