
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-14504 is an authorization bypass vulnerability in Sonatype Nexus Repository 3's component upload API that allows a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check. It was disclosed on July 14, 2026, and affects Nexus Repository 3 versions 3.88.0 through 3.93.x (specifically: Terraform hosted repositories from 3.88.0+, Swift from 3.89.0+, and Conda from 3.91.0+). The vulnerability is fixed in version 3.94.0. It carries a CVSS v4.0 base score of 8.2 (High) (Sonatype Advisory, Sonatype Release Notes).
The root cause is CWE-862 (Missing Authorization) — the component upload API endpoint (POST /service/rest/v1/components) fails to enforce write/edit permission checks for Swift, Terraform, and Conda hosted repository formats, allowing a principal with only read/browse privileges to successfully upload artifacts. The attack vector is network-based and requires no user interaction; however, exploitation requires the attacker to have at least read/browse access to an affected repository, either via an authenticated account or via the anonymous role if global anonymous access is enabled on the instance. On instances with anonymous access enabled, the default anonymous role grants read/browse access to all repositories, making the vulnerability exploitable without any credentials (Sonatype Advisory).
Successful exploitation allows an attacker to publish arbitrary, potentially malicious artifacts to trusted hosted repositories (Swift, Terraform, or Conda), directly threatening software supply chain integrity. Downstream consumers — developers, CI/CD pipelines, or automated build systems — pulling from the compromised repository could receive attacker-controlled packages, enabling dependency confusion attacks, malware distribution, or backdoor injection. Confidentiality and availability are not directly impacted, but the integrity impact is rated High (Sonatype Advisory).
As of the disclosure date (July 14, 2026), Sonatype reports no known active exploitation of this vulnerability in the wild. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.26%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is more accessible on instances with anonymous access enabled, where no credentials are required, but is otherwise limited to authenticated users with at least read/browse access (Sonatype Advisory).
POST /service/rest/v1/components?repository=<target-repo>.POST /service/rest/v1/components requests to Nexus Repository 3 instances, particularly from accounts or IP addresses not normally associated with artifact publishing; requests targeting Swift, Terraform, or Conda hosted repositories.POST /service/rest/v1/components events attributed to accounts holding only read/browse roles on Swift, Terraform, or Conda repositories, or attributed to the anonymous principal; successful upload responses (HTTP 204) from such accounts.Sonatype recommends upgrading all affected Nexus Repository 3 CE/Pro instances to version 3.94.0 or later, which contains the fix for this vulnerability. For those unable to upgrade immediately, Sonatype recommends the following interim mitigations: (1) Review and revoke unnecessary read/browse role grants on Swift, Terraform, and Conda hosted repositories; (2) Set the repository write policy to DENY on affected hosted repositories to block all uploads; (3) If global anonymous access is enabled and not required, disable it via Administration > Security > Anonymous Access; (4) Monitor audit logs for unauthorized POST /service/rest/v1/components requests from low-privilege or anonymous accounts (Sonatype Advisory, Sonatype Release Notes).
The vulnerability was discovered and responsibly reported by security researcher muhammaddaffa through Sonatype's Bug Bounty Program, and Sonatype followed a responsible disclosure process by publishing a detailed advisory on the same day as the fix release. No significant broader media coverage or notable researcher commentary beyond the official advisory has been identified at this time (Sonatype Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."