CVE-2026-14644: Sonatype Nexus Repository Manager
High severity, CVSS 7.2. EPSS: 0.3% chance of exploitation in the next 30 days.
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint.
Affected products
- Sonatype Nexus Repository Manager: from 3.19.0, before 3.95.0 (fixed in 3.95.0)
Published 2026-08-07. Last modified 2026-09-22.