CVE-2026-92782: Chroma through 1.5.9 Authorization Bypass via Collection Identifier
Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Chromato a version that resolves this vulnerability.Fixed in 1.5.9
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated attacker can exploit it. They need to know the identifier of a collection belonging to another tenant; no user interaction is required.
What access could an attacker gain?
An attacker can access collections from other tenants despite making requests under their own tenant path. The described impact includes reading, modifying, and updating records in foreign collections.
Which versions are affected?
Chroma through version 1.5.9 is affected.