{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3achromachroma/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:chroma:chroma:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92782"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Chroma (\u003c= 1.5.9)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","authorization-bypass","chroma"],"_cs_type":"advisory","_cs_vendors":["Chroma"],"content_html":"\u003cp\u003eChroma, a vector database, contains a critical authorization flaw in versions up to and including 1.5.9. The vulnerability arises from a failure to validate tenant and database segments when the application resolves collections. Because the system does not enforce strict tenant isolation during the request resolution process, an authenticated attacker who is aware of a collection identifier belonging to another tenant can interact with that collection as if they were authorized. This flaw allows unauthorized read, update, and delete operations on foreign data, effectively breaking the multi-tenancy model. Attackers can reach these foreign collections by issuing requests under their own legitimate tenant path, circumventing the intended security boundaries. Given the role of vector databases in RAG (Retrieval-Augmented Generation) architectures, this vulnerability could lead to the exposure of sensitive proprietary or private documents indexed within unauthorized collections.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized information disclosure, unauthorized modification of records, and data destruction across tenant boundaries. This impact is significant for multi-tenant deployments, such as SaaS providers or enterprise environments managing multiple teams' data in a single Chroma cluster. The scope is limited to authenticated users of the platform, who can leverage their existing access to escalate their reach to any collection for which they can determine the identifier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Chroma deployments to a version beyond 1.5.9 immediately to incorporate required tenant and database segment validation.\u003c/li\u003e\n\u003cli\u003eReview access logs for an abnormal frequency of requests targeting collection identifiers not typically associated with the requesting tenant ID.\u003c/li\u003e\n\u003cli\u003eImplement monitoring at the API gateway layer to validate that the tenant ID present in the authenticated session matches the tenant context requested within the URI or query parameters for collection operations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-16T21:56:18Z","date_published":"2026-09-16T21:56:18Z","id":"https://feed.craftedsignal.io/briefs/2026-09-chroma-auth-bypass/","summary":"Chroma versions 1.5.9 and earlier are vulnerable to an authorization bypass allowing authenticated users to access, modify, and delete cross-tenant data by manipulating collection identifiers.","title":"Authorization Bypass in Chroma via Tenant Isolation Failure","url":"https://feed.craftedsignal.io/briefs/2026-09-chroma-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:chroma:chroma:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}