CVE-2026-45831: Trychroma Chromadb
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
Affected products
- Trychroma Chromadb: from 0.5.0, up to and including 1.5.9
Published 2026-06-12. Last modified 2026-06-17.