CVE-2026-45830: High severity pypi/chromadb vulnerability
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45830?
The severity of CVE-2026-45830 is rated high with a score of 8.8 according to the CVSS.
How do I fix CVE-2026-45830?
To fix CVE-2026-45830, upgrade to a version of ChromaDB that includes proper authorization validation.
What impact does CVE-2026-45830 have on users?
CVE-2026-45830 allows any authenticated user to access and manipulate data across tenants, potentially impacting data confidentiality and integrity.
Which versions of ChromaDB are affected by CVE-2026-45830?
CVE-2026-45830 affects all versions of the ChromaDB Python project from version 0.4.17 and later.
Who is at risk due to CVE-2026-45830?
Any organization using ChromaDB version 0.4.17 or later is at risk due to the lack of authorization validation.