Project Management API Vulnerability in Nuclio by Igneous Systems
CVE-2026-45730
8.3HIGH
What is CVE-2026-45730?
A vulnerability exists in the Nuclio Dashboard's project management API that allows any authenticated user to bypass Open Policy Agent (OPA) authorization checks. This flaw enables unauthorized modifications or deletions of projects and their associated resources, such as functions and API gateways. The issue was patched in version 1.16.0, highlighting the importance of keeping the software updated to mitigate potential security risks.
Affected Version(s)
nuclio < 1.16.0
