The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
References
| Link | Resource |
|---|---|
| https://www.hiddenlayer.com/sai-security-advisory/2026-06-chromadb-3 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-06-12 16:16
Updated : 2026-06-17 10:52
NVD link : CVE-2026-45831
Mitre link : CVE-2026-45831
CVE.ORG link : CVE-2026-45831
JSON object : View
Products Affected
trychroma
- chromadb
CWE
CWE-863
Incorrect Authorization
