CVE-2026-14504: Sonatype Nexus Repository Manager

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.

Affected products

  • Sonatype Nexus Repository Manager: from 3.88.0, before 3.94.0 (fixed in 3.94.0)

Published 2026-07-14. Last modified 2026-09-22.