Junglewise Threat Intelligence

CVE-2026-14504: Sonatype Nexus Repository 3 authorization bypass in component upload API

CVE-2026-14504 · Severity: info · CVSS 8.2 · Published 2026-07-14

Technologies: Sonatype Nexus Repository 3. Vendors: Sonatype.

Executive brief

Sonatype Nexus Repository 3, a platform used by software teams to store and manage code components, contains a security flaw in its upload system. This vulnerability allows users who should only be able to view or download files to instead upload their own files into Swift, Terraform, or Conda repositories. This could allow an unauthorized person to inject malicious code or unauthorized software into a company's development pipeline, potentially compromising the integrity of software builds.

Technical details

A missing authorization check (CWE-862) exists in the component upload API of Sonatype Nexus Repository 3. The vulnerability specifically affects Swift, Terraform, and Conda hosted repositories. An attacker with existing read or browse privileges can bypass intended write-permission checks to upload arbitrary artifacts via the API. This could lead to the injection of malicious components into the repository. The issue is resolved in Nexus Repository version 3.94.0.

Affected products

  • Sonatype Nexus Repository 3 3.88.0 to 3.93.2

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats