The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
CVSS
No CVSS.
References
Configurations
No configuration.
History
12 Jun 2026, 16:23
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-12 16:16
Updated : 2026-06-12 16:23
NVD link : CVE-2026-45831
Mitre link : CVE-2026-45831
CVE.ORG link : CVE-2026-45831
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
