CVE-2026-14504: Nexus Repository 3 - Authorization Bypass in Component Upload API
Published Jul 14, 2026
·Updated
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.
Affected Software
1 affected component
Sonatype Nexus Repository 3
Event History
Jul 14, 2026
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionWeakness
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-14504?
The severity of CVE-2026-14504 is rated as high with a CVSS score of 8.2.
2
What does CVE-2026-14504 describe?
CVE-2026-14504 describes an authorization bypass vulnerability in Nexus Repository 3's component upload API.
3
How does CVE-2026-14504 impact users?
CVE-2026-14504 allows users with only read/browse privileges to upload arbitrary artifacts, violating intended write-permission checks.
4
How do I fix CVE-2026-14504?
To fix CVE-2026-14504, ensure that proper access controls and permissions are enforced on the component upload API.
5
Which software is affected by CVE-2026-14504?
CVE-2026-14504 affects Sonatype Nexus Repository 3.