CVE-2026-45831

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
CVSS

No CVSS.

Configurations

No configuration.

History

12 Jun 2026, 16:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-12 16:16

Updated : 2026-06-12 16:23


NVD link : CVE-2026-45831

Mitre link : CVE-2026-45831

CVE.ORG link : CVE-2026-45831


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization