OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-92782 (CVSS 8.6)

NVD · officialPublished Sep 16, 2026Risk 37/100EPSS 0.3%

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.

CVSS
8.6
AV:NetworkAC:LowPR:LowUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source