Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-45830

Опубликовано: 12 июн. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

A flaw was found in ChromaDB. A lack of authorization validation in the ChromaDB Python project allows any authenticated user to read, write, update, or delete data in any tenant's collection. This means an attacker can bypass intended access controls and manipulate data across different tenants, leading to unauthorized data access and modification.

Отчет

This flaw is Post-authentication IDOR: ChromaDB resolves collections by UUID without tenant/database filtering, allowing any authenticated user who knows a collection UUID to access any tenant’s data. High severity for confidentiality and integrity; not Critical because authentication is required and there is no code execution or availability impact.

Меры по смягчению последствий

To reduce the attack surface, restrict network access to ChromaDB instances to only trusted clients and internal networks. Implement network segmentation and firewall rules to limit exposure of the ChromaDB service. This operational control helps prevent unauthorized access to the service, although it does not address the internal authorization bypass for already authenticated users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gaudi-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/disk-image-cuda-rhel9Will not fix
Red Hat OpenShift AI (RHOAI)rhoai/odh-autorag-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-266
https://bugzilla.redhat.com/show_bug.cgi?id=2488408chromadb: ChromaDB: Unauthorized data manipulation due to improper authorization validation

EPSS

Процентиль: 27%
0.00345
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

CVSS3: 8.8
github
около 2 месяцев назад

A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

EPSS

Процентиль: 27%
0.00345
Низкий

8.1 High

CVSS3