PT-2026-48895 · Pypi · Chromadb

CVE-2026-45830

·

Published

2026-06-12

·

Updated

2026-09-10

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions ChromaDB versions 0.4.17 and later
Description Lack of authorization validation in the ChromaDB Python project allows any authenticated user to read, write, update, or delete data in any tenant's collection. This flaw enables an attacker to bypass intended access controls and manipulate data across different tenants, leading to unauthorized data access and modification.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Privilege Assignment

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45830
GHSA-2WM9-HF6C-P5CR
PYSEC-2026-3813

Affected Products

Chromadb