CVE-2026-45831
Vulnerability Description
The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
Affected Platforms (CPE)
No CPE configurations currently published for this record.
