CyberSec.Space Logo
Back to CVE Browser

CVE-2026-45831

PENDING
N/A
CVSS Severity Score
EPSS Score0.0510%
EPSS Percentile14.47th
PublishedJun 12, 2026
Last ModifiedJun 12, 2026

Vulnerability Description

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

Related Vulnerabilities