PT-2026-94059 · Chroma · Chroma

·

CVE-2026-92782

·

Published

2026-09-16

·

Updated

2026-09-19

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Chroma versions prior to 1.6.0
Description Authenticated attackers can access collections belonging to other tenants if they possess the collection identifier. This occurs because the software fails to validate tenant and database segments during collection resolution. By issuing requests under their own tenant path, attackers can bypass authorization checks to read, modify, and update records in foreign collections.
Recommendations Update to version 1.6.0 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92782

Affected Products

Chroma