Vulnerability Description
Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated user (without membership in the target project) to bypass OPA authorization checks on write paths (PUT /api/projects/{id}, DELETE /api/projects) and modify or delete any project along with all its associated resources (functions, API gateways, etc.). This issue has been patched in version 1.16.0.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/nuclio/nuclio/commit/1915cd26d514dcdd487517d4be56673fc02298e0
- https://github.com/nuclio/nuclio/pull/4107
- https://github.com/nuclio/nuclio/releases/tag/1.16.0
- https://github.com/nuclio/nuclio/security/advisories/GHSA-m8xg-8xg9-mxhm
- https://github.com/nuclio/nuclio/security/advisories/GHSA-m8xg-8xg9-mxhm
FAQ
What is CVE-2026-45730?
CVE-2026-45730 is a vulnerability with a CVSS score of 8.3 (HIGH). Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.0, there is a vulnerability in Nuclio Dashboard's project management API, allowing any authenticated ...
How severe is CVE-2026-45730?
CVE-2026-45730 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45730?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.