Authorization Bypass Vulnerability in Chroma by Chroma Core
CVE-2026-92782
8.6HIGH
What is CVE-2026-92782?
Chroma versions up to 1.5.9 are susceptible to an authorization bypass vulnerability that allows authenticated attackers to access collections belonging to other tenants. This occurs due to inadequate validation of tenant and database segments during the resolution of collections. An attacker who knows a collection identifier can manipulate requests to their own tenant path, effectively circumventing the necessary authorization checks. Consequently, this flaw permits unauthorized users to read, modify, and update records across foreign collections, compromising data integrity and security.
Affected Version(s)
chroma 0 <= 1.5.9
