Authorization Bypass Vulnerability in Chroma by Chroma Core
CVE-2026-92782

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92782?

Chroma versions up to 1.5.9 are susceptible to an authorization bypass vulnerability that allows authenticated attackers to access collections belonging to other tenants. This occurs due to inadequate validation of tenant and database segments during the resolution of collections. An attacker who knows a collection identifier can manipulate requests to their own tenant path, effectively circumventing the necessary authorization checks. Consequently, this flaw permits unauthorized users to read, modify, and update records across foreign collections, compromising data integrity and security.

Affected Version(s)

chroma 0 <= 1.5.9

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.