← Back to overview

A vulnerability exists in the Nuclio Serverless framework's Dashboard project management API prior to version 1.16.0. Any authenticated user, regardless of project membership, can bypass OPA (Open Policy Agent) authorization checks on write paths. Specifically, the PUT /api/projects/{id} and DELETE /api/projects endpoints are affected. Exploitation allows unauthorized modification or deletion of any project and all associated resources including functions and API gateways. The vulnerability does not require elevated privileges, only valid authentication. The issue has been fully patched in Nuclio version 1.16.0. Users are advised to upgrade immediately to mitigate unauthorized access risks. The fix is documented in a public GitHub commit, pull request, and security advisory.

Affected products

  • Nuclio Serverless Framework (prior to version 1.16.0)

Related CVE's

  • CVE-2026-45730

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Web Technologies