CVE-2026-45831
HIGH WAF: Low
CVSS 8.8
Published: 2026-06-12
CWE-863
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
WAF Coverage Analysis
Incorrect Authorization
Low WAF Coverage
OWASP: A01:2021 Broken Access Control
Affected Software
| Vendor | Product | Version |
|---|---|---|
| trychroma | chromadb | 0.5.0 - 1.5.9 |
References
- www.hiddenlayer.com (Third Party Advisory)