A max-severity vulnerability (CVE-2026-45829, CVSS 10.0) was disclosed affecting ChromaDB, the widely used open-source vector database for AI applications, allowing attackers to achieve unauthenticated remote code execution via a logic flaw in the Python FastAPI server’s authentication flow. Due to the potential for full server compromise, immediate mitigation is required for all internet-facing deployments. About […] The post Critical Pre-Auth RCE in ChromaDB Threatens AI Infrastructure appeared first on Orca Security .