{"id":"CVE-2026-45831","aliases":["GHSA-xph7-9rjv-w5fr","PYSEC-2026-3815"],"title":"ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to","summary":"ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"chromadb","product":"chromadb","ecosystem":"pip","affected":["chromadb >= 0.5.0, <= 1.5.9"],"published":"2026-06-12","updated":"2026-09-10","sourceUpdated":"2026-09-10T12:25:45.510140945Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-xph7-9rjv-w5fr","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45831"},{"url":"https://github.com/chroma-core/chroma/issues/7588"},{"url":"https://github.com/chroma-core/chroma/pull/7602"},{"url":"https://github.com/chroma-core/chroma"},{"url":"https://www.hiddenlayer.com/sai-security-advisory/2026-06-chromadb-3"},{"url":"https://pypi.org/project/chromadb"},{"url":"https://github.com/advisories/GHSA-xph7-9rjv-w5fr"}],"tags":["osv","pip"],"epss":0.00237,"epssPercentile":0.14969,"ingestedAt":"2026-08-25T19:26:22.723Z","slug":"CVE-2026-45831","body":"## Overview\n\nThe SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.\n\n## Affected packages\n\n- `chromadb >= 0.5.0, <= 1.5.9`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}