Home

Description

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

PUBLISHED Reserved 2026-05-13 | Published 2026-06-12 | Updated 2026-06-12 | Assigner HiddenLayer




HIGH: 8.8CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Problem types

CWE-863: Incorrect Authorization

Product status

Default status
unaffected

0.5.0 (custom)
affected

References

www.hiddenlayer.com/sai-security-advisory/2026-06-chromadb-3

cve.org (CVE-2026-45831)

nvd.nist.gov (CVE-2026-45831)

Download JSON