Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 16 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Trychroma
Trychroma chromadb |
|
| CPEs | cpe:2.3:a:trychroma:chromadb:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Trychroma
Trychroma chromadb |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 15 Jun 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | ChromaDB: ChromaDB: Unauthorized cross-tenant actions due to improper authorization checks | |
| Weaknesses | CWE-1220 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 12 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 12 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chroma
Chroma chromadb |
|
| Vendors & Products |
Chroma
Chroma chromadb |
Fri, 12 Jun 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions. | |
| Weaknesses | CWE-863 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: HiddenLayer
Published:
Updated: 2026-06-12T16:22:00.578Z
Reserved: 2026-05-13T14:01:39.604Z
Link: CVE-2026-45831
Updated: 2026-06-12T16:21:50.679Z
Status : Analyzed
Published: 2026-06-12T16:16:28.797
Modified: 2026-06-16T15:07:38.287
Link: CVE-2026-45831
OpenCVE Enrichment
Updated: 2026-06-15T15:00:10Z