CVE-2026-45831: Trychroma Chromadb

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

Affected products

  • Trychroma Chromadb: from 0.5.0, up to and including 1.5.9

Published 2026-06-12. Last modified 2026-06-17.