Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-45831

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 13.1%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2026-45831


Contact Us

Shodan ® - All rights reserved