Description
Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.
Published: 2026-09-16
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass through collection ID validation flaw
Action: Apply Patch
AI Analysis

Impact

Chroma through version 1.5.9 does not verify the tenant and database segments when resolving a collection, allowing an attacker who has authenticated access to read, modify or delete records in collections belonging to other tenants. This flaw enables the attacker to bypass normal authorization checks, effectively granting cross‑tenant access to data. The weakness corresponds to CWE‑863, which describes inadequate enforcement of authorization policies.

Affected Systems

Chroma Core (chroma‑core:chroma) – all releases up to and including 1.5.9 are affected. Users should check their installed version and apply the patch if they are running 1.5.9 or an earlier release.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.6, indicating high severity. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the issue has not been listed in the CISA KEV catalog. Likely exploitation requires an authenticated user who knows the target collection identifier and can send requests under their own tenant path; the attacker then receives data from or modifies the foreign collection without permission.

Generated by OpenCVE AI on September 18, 2026 at 06:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Chroma to a version newer than 1.5.9 where tenant validation is enforced during collection resolution.
  • If an immediate upgrade is not feasible, isolate tenants by restricting API access to collection endpoints or enabling any available configuration that enforces tenant scoping until the patch is applied.
  • Actively monitor access logs for anomalous cross‑tenant queries and revoke or audit privileges that could be used to issue arbitrary collection ID requests.

Generated by OpenCVE AI on September 18, 2026 at 06:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Chroma-core
Chroma-core chroma
Vendors & Products Chroma-core
Chroma-core chroma

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.
Title Chroma through 1.5.9 Authorization Bypass via Collection Identifier
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Chroma-core Chroma
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T01:40:22.908Z

Reserved: 2026-09-16T19:22:54.200Z

Link: CVE-2026-92782

cve-icon Vulnrichment

Updated: 2026-09-19T01:40:12.081Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:27.280

Modified: 2026-09-24T21:00:46.893

Link: CVE-2026-92782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:30:05Z

Weaknesses