CVE-2026-8828 - ChromaDB Authorization Bypass
CVE ID :CVE-2026-8828
Published : June 12, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 12, 2026, 4:16 p.m. | 1 hour, 29 minutes ago
Description :A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.
Severity: 8.8 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...