CVE-2026-45830: CWE-639 Authorization bypass through User-Controlled key in Chroma ChromaDB
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.
AI Analysis
Technical Summary
The vulnerability identified as CVE-2026-45830 affects ChromaDB Python project starting from version 0.4.17. It is categorized under CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-266 (Incorrect Access Control). Due to insufficient authorization checks, authenticated users can perform arbitrary data operations on collections belonging to other tenants, violating tenant isolation. The CVSS 4.0 base score is 8.8, indicating high severity with network attack vector, low attack complexity, and requiring privileges but no user interaction. No official patch or remediation level is currently provided by the vendor. The Red Hat advisory linked does not specify a fix or mitigation, and no known exploits are reported in the wild.
Potential Impact
Successful exploitation allows any authenticated user to bypass tenant boundaries and perform unauthorized read, write, update, or delete operations on data belonging to other tenants. This compromises data confidentiality, integrity, and availability across tenant collections within ChromaDB. The impact is high due to the broad scope of unauthorized access and modification capabilities.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or remediation level is indicated in the vendor advisory, users should monitor the vendor's security advisories for updates. Until a patch is available, restrict authenticated user privileges where possible and consider additional access control mechanisms external to ChromaDB to enforce tenant isolation.
CVE-2026-45830: CWE-639 Authorization bypass through User-Controlled key in Chroma ChromaDB
Description
A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.
CVSS v4.0
Score 8.8high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability identified as CVE-2026-45830 affects ChromaDB Python project starting from version 0.4.17. It is categorized under CWE-639 (Authorization Bypass Through User-Controlled Key) and CWE-266 (Incorrect Access Control). Due to insufficient authorization checks, authenticated users can perform arbitrary data operations on collections belonging to other tenants, violating tenant isolation. The CVSS 4.0 base score is 8.8, indicating high severity with network attack vector, low attack complexity, and requiring privileges but no user interaction. No official patch or remediation level is currently provided by the vendor. The Red Hat advisory linked does not specify a fix or mitigation, and no known exploits are reported in the wild.
Potential Impact
Successful exploitation allows any authenticated user to bypass tenant boundaries and perform unauthorized read, write, update, or delete operations on data belonging to other tenants. This compromises data confidentiality, integrity, and availability across tenant collections within ChromaDB. The impact is high due to the broad scope of unauthorized access and modification capabilities.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or remediation level is indicated in the vendor advisory, users should monitor the vendor's security advisories for updates. Until a patch is available, restrict authenticated user privileges where possible and consider additional access control mechanisms external to ChromaDB to enforce tenant isolation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- HiddenLayer
- Date Reserved
- 2026-05-13T14:01:39.604Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-45830","vendor":"Red Hat"}]
Threat ID: 6a2c2836e617e2d83487d70e
Added to database: 06/12/2026, 15:39:34 UTC
Last enriched: 07/31/2026, 13:01:13 UTC
Last updated: 07/31/2026, 19:31:23 UTC
Views: 87
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.