Auth Bypass: Nexus Repository 3 Upload API
CVE-2026-14504 Published on July 14, 2026

Nexus Repository 3 - Authorization Bypass in Component Upload API
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.

Vendor Advisory NVD

Weakness Type

What is an AuthZ Vulnerability?

The software does not perform an authorization check when an actor attempts to access a resource or perform an action.

CVE-2026-14504 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-14504

Want to know whenever a new CVE is published for Sonatype Nexus Repository Manager? stack.watch will email you.

 

Affected Versions

Sonatype Nexus Repository 3: