CVE-2026-45730

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project) to bypass OPA authorization checks on write paths (PUT /api/projects/{id}, DELETE /api/projects) and modify or delete any project along with all its associated resources (functions, API gateways, etc.). This issue has been patched in version 1.16.0.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 17:17

Updated : 2026-09-09 21:04


NVD link : CVE-2026-45730

Mitre link : CVE-2026-45730

CVE.ORG link : CVE-2026-45730


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization