๐Ÿ” CVE Alert

CVE-2026-45831

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

CWE CWE-863
Vendor chroma
Product chromadb
Published Jun 12, 2026
Last Updated Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for chroma chromadb

Be the first to know when new unknown vulnerabilities affecting chroma chromadb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Chroma / ChromaDB
0.5.0 โ‰ค *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hiddenlayer.com: https://www.hiddenlayer.com/sai-security-advisory/2026-06-chromadb-3