Security Advisory

CVE-2026-45832

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-12 15:11:46
Last updated 2026-07-15 00:52:09
Assigner HiddenLayer
CVSS score 8.8
State PUBLISHED

Description

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.