Fiche vulnérabilité
CVE-2026-45830 : faille élevée trychroma chromadb (CVSS 8.8)
Description
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.
En bref
- Sévérité
- Élevée (CVSS 8.8)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 12 juin 2026
- Dernière mise à jour
- 15 juil. 2026
Produits concernés
- trychroma chromadb