An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-14 16:16
Updated : 2026-07-15 20:08
NVD link : CVE-2026-14504
Mitre link : CVE-2026-14504
CVE.ORG link : CVE-2026-14504
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
