SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-14504

HIGH · CVSS 8.2 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Nexus Repository 3's component upload API is vulnerable to an authorization bypass, enabling users with only read or browse privileges on Swift, Terraform, or Conda hosted repositories to upload arbitrary artifacts. This flaw compromises the integrity of the repository by allowing unauthorized content to be introduced. Organizations utilizing Nexus Repository 3 should prioritize addressing this vulnerability to prevent potential exploitation and maintain repository security.

CVE
CVE-2026-14504
Severity
HIGH
CVSS
8.2
EPSS
0.26%

Original NVD Description

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.