CVE-2026-14644: Nexus Repository 3 - Privilege Escalation
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14644?
CVE-2026-14644 has a risk score of 56, indicating a medium level of severity.
How do I fix CVE-2026-14644?
To fix CVE-2026-14644, update Sonatype Nexus Repository 3 to the latest recommended version that addresses this privilege escalation flaw.
Who is affected by CVE-2026-14644?
Authenticated users of Sonatype Nexus Repository 3 who have permission to manage privileges are affected by CVE-2026-14644.
What does CVE-2026-14644 exploit?
CVE-2026-14644 exploits a type-confusion flaw in the REST privileges API for privilege escalation.
What is the impact of CVE-2026-14644?
The impact of CVE-2026-14644 is that an authenticated user can escalate their access to full administrator rights.