Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

A critical unauthenticated remote code execution vulnerability (CVE-2026-45829) has been identified in ChromaDB’s Python FastAPI server, affecting versions 1.0.0 through 1.5.8. Any attacker with network access to an exposed ChromaDB instance can execute arbitrary code on the server before authentication is ever checked, with no credentials required. Organizations using ChromaDB in AI pipelines or vector search infrastructure face complete server compromise; no confirmed vendor patch exists as of 2026-03-04.

Author

Tech Jacks Solutions