CVE-2026-45830High· 8.8▾ TwilightChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 25.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.3%
Last analysed / modified upstream
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.
chromadb >= 0.4.17, <= 1.5.9Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.