---
id: CVE-2026-45831
aliases:
  - GHSA-xph7-9rjv-w5fr
  - PYSEC-2026-3815
title: >-
  ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant,
  database, or collection a permission applies to
summary: >-
  ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant,
  database, or collection a permission applies to
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: chromadb
product: chromadb
ecosystem: pip
affected:
  - 'chromadb >= 0.5.0, <= 1.5.9'
published: '2026-06-12'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T12:25:45.510140945Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-xph7-9rjv-w5fr'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-45831'
  - url: 'https://github.com/chroma-core/chroma/issues/7588'
  - url: 'https://github.com/chroma-core/chroma/pull/7602'
  - url: 'https://github.com/chroma-core/chroma'
  - url: 'https://www.hiddenlayer.com/sai-security-advisory/2026-06-chromadb-3'
  - url: 'https://pypi.org/project/chromadb'
  - url: 'https://github.com/advisories/GHSA-xph7-9rjv-w5fr'
tags:
  - osv
  - pip
epss: 0.00422
epssPercentile: 0.33997
ingestedAt: '2026-08-25T19:26:22.723Z'
---

## Overview

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

## Affected packages

- `chromadb >= 0.5.0, <= 1.5.9`

## Remediation

Refer to the advisory for the patched release.
