Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-45831

Опубликовано: 12 июн. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trychroma:chromadb:*:*:*:*:*:python:*:*
Версия от 0.5.0 (включая) до 1.5.9 (включая)

EPSS

Процентиль: 14%
0.00237
Низкий

8.8 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 6.8
redhat
9 дней назад

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

CVSS3: 8.8
github
9 дней назад

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.

EPSS

Процентиль: 14%
0.00237
Низкий

8.8 High

CVSS3

Дефекты

CWE-863