A AegiFlow
HIGHCVSS 8.8EPSS 0.3%

CVE-2026-45830

ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

Published
2026-06-12
Modified
2026-08-24
EPSS percentile
27%
Aliases
GHSA-2wm9-hf6c-p5cr
Sources
github-advisory

Summary

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

Affected packages

EcosystemPackageAffected versionsFixed versions
PyPIchromadb

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.