Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-8828

Опубликовано: 12 июн. 2026
Источник: nvd
EPSS Низкий

Описание

A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

EPSS

Процентиль: 20%
0.00279
Низкий

Дефекты

CWE-639

Связанные уязвимости

github
3 месяца назад

A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

EPSS

Процентиль: 20%
0.00279
Низкий

Дефекты

CWE-639