CVE-2026-92782

Source
https://cve.org/CVERecord?id=CVE-2026-92782
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92782.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92782
Published
2026-09-16T20:32:39Z
Modified
2026-09-18T03:48:43Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Chroma through 1.5.9 Authorization Bypass via Collection Identifier
Details

Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated attackers to access collections from other tenants by knowing the collection identifier. Attackers can read, modify, and update records in foreign collections by issuing requests under their own tenant path, bypassing authorization checks.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92782.json"
}
References

Affected packages

Git / github.com/chroma-core/chroma

Affected ranges

Type
GIT
Repo
https://github.com/chroma-core/chroma
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.5.9"
        },
        {
            "fixed": "1.5.9"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

0.*
0.0.2
0.1.0
0.2.0
0.3.0
0.3.1
0.3.10
0.3.11
0.3.12
0.3.13
0.3.14
0.3.15
0.3.16
0.3.18
0.3.19
0.3.2
0.3.21
0.3.22
0.3.23
0.3.24
0.3.25
0.3.26
0.3.27
0.3.28
0.3.29
0.3.3
0.3.4
0.3.5
0.3.6
0.3.7
0.3.8
0.3.9
0.4.0
0.4.1
0.4.10
0.4.2
0.4.3
0.4.4
0.4.5
0.4.6
0.4.7
0.4.8
0.4.9
js_release_1.*
js_release_1.5.7
js_release_1.5.8
js_release_alpha_1.*
js_release_alpha_1.5.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92782.json"