NONE · 0

CVE-2026-8828

A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection r...

Vulnerability Description

A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-8828?

CVE-2026-8828 is a documented vulnerability. A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection r...

How severe is CVE-2026-8828?

CVSS scoring is not yet available for CVE-2026-8828. Check NVD for updates.

Is there a patch for CVE-2026-8828?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.