Auth Bypass: Nexus Repository 3 Upload API
CVE-2026-14504 Published on July 14, 2026
Nexus Repository 3 - Authorization Bypass in Component Upload API
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-14504 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-14504
Want to know whenever a new CVE is published for Sonatype Nexus Repository Manager? stack.watch will email you.
Affected Versions
Sonatype Nexus Repository 3:- Version 3.88.0 and below 3.94.0 is affected.