# CVE-2026-14504

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.

Published Jul 3, 2026

### CVE-2026-14504 Security Details

**CVE ID**  
CVE-2026-14504

**CWE**  
CWE-862 [Learn more about CWE-862](https://cwe.mitre.org/data/definitions/862.html)

**CVE Description**  
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.

**Published**  
Jul 3, 2026

**CVSS Score & Severity**  
8.2 High

**CVSS Vector**  
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

**EPSS Score**  
0%

**Malware**  
malware

**KEV Status**  
Not in KEV Catalog: No known exploits

**Affected Ecosystems**  
affected

**Source**  
National Vulnerability Database

**References**  
[support.sonatype.com](https://support.sonatype.com/hc/en-us/articles/53137654741907/ "https://support.sonatype.com/hc/en-us/articles/53137654741907/")
