CyberRota
← Ana sayfaya dön

CVE-2026-45831

HIGH · CVSS 8.8 EPSS %0.24

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-12T16:16:28.797 · Çekilme zamanı: 2026-06-30T18:20:19.219202+00:00

CyberRota Yorumu

Detaylı analiz gerekiyor.

CVE
CVE-2026-45831
Severity
HIGH
CVSS
8.8
EPSS
%0.24

Orijinal NVD Açıklaması

The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.