CVE-2026-14504 | Security Details | Sonatype Guide

CVE-2026-14504

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.

Published Jul 3, 2026

CVE-2026-14504 Security Details

CVE ID
CVE-2026-14504

CWE
CWE-862 Learn more about CWE-862

CVE Description
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.

Published
Jul 3, 2026

CVSS Score & Severity
8.2 High

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

EPSS Score
0%

Malware
malware

KEV Status
Not in KEV Catalog: No known exploits

Affected Ecosystems
affected

Source
National Vulnerability Database

References
support.sonatype.com