MajorCritical vulnerability
CVE-2026-92782 (CVSS 8.6)
NVD · officialPublished Sep 16, 2026Risk 37/100EPSS 0.3%
Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.
Technical details
CVSS
8.6
AV:NetworkAC:LowPR:LowUI:None
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source