Aller au contenu

Fiche vulnérabilité

CVE-2026-45830 : faille élevée trychroma chromadb (CVSS 8.8)

Description

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
12 juin 2026
Dernière mise à jour
15 juil. 2026

Produits concernés

  • trychroma chromadb

Références

Rechercher une autre vulnérabilité dans la base CVE