Beveiligingsadvies

CVE-2026-45832

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-12 15:11:46
Laatst bijgewerkt 2026-07-31 12:04:47
Toegewezen door HiddenLayer
CVSS-score 8.8
Status PUBLISHED

Beschrijving

All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.