CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. See the original NVD description below for full technical details.
CVE
CVE-2026-45832
Severity
HIGH
CVSS
8.8
EPSS
0.28%
Original NVD Description
All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.
Related CVEs
Other vulnerabilities affecting the same vendor(s)