CVE-2026-45832
Chroma ChromaDB, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI)
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.
- CVSS
- 8.8
- EPSS
- 0.28% 20.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.13