CVE-2026-14504
Sonatype Nexus 3 vulnerability analysis and mitigation

Overview

CVE-2026-14504 is an authorization bypass vulnerability in Sonatype Nexus Repository 3's component upload API that allows a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check. It was disclosed on July 14, 2026, and affects Nexus Repository 3 versions 3.88.0 through 3.93.x (specifically: Terraform hosted repositories from 3.88.0+, Swift from 3.89.0+, and Conda from 3.91.0+). The vulnerability is fixed in version 3.94.0. It carries a CVSS v4.0 base score of 8.2 (High) (Sonatype Advisory, Sonatype Release Notes).

Technical details

The root cause is CWE-862 (Missing Authorization) — the component upload API endpoint (POST /service/rest/v1/components) fails to enforce write/edit permission checks for Swift, Terraform, and Conda hosted repository formats, allowing a principal with only read/browse privileges to successfully upload artifacts. The attack vector is network-based and requires no user interaction; however, exploitation requires the attacker to have at least read/browse access to an affected repository, either via an authenticated account or via the anonymous role if global anonymous access is enabled on the instance. On instances with anonymous access enabled, the default anonymous role grants read/browse access to all repositories, making the vulnerability exploitable without any credentials (Sonatype Advisory).

Impact

Successful exploitation allows an attacker to publish arbitrary, potentially malicious artifacts to trusted hosted repositories (Swift, Terraform, or Conda), directly threatening software supply chain integrity. Downstream consumers — developers, CI/CD pipelines, or automated build systems — pulling from the compromised repository could receive attacker-controlled packages, enabling dependency confusion attacks, malware distribution, or backdoor injection. Confidentiality and availability are not directly impacted, but the integrity impact is rated High (Sonatype Advisory).

Exploitability

As of the disclosure date (July 14, 2026), Sonatype reports no known active exploitation of this vulnerability in the wild. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.26%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is more accessible on instances with anonymous access enabled, where no credentials are required, but is otherwise limited to authenticated users with at least read/browse access (Sonatype Advisory).

Exploitation steps

  1. Reconnaissance: Identify Nexus Repository 3 instances running versions 3.88.0–3.93.x that have Swift, Terraform, or Conda hosted repositories configured. Use Shodan, Censys, or direct network scanning to locate exposed instances.
  2. Assess anonymous access: Determine whether the target instance has global anonymous access enabled (commonly indicated by the ability to browse repositories without authentication). If enabled, no credentials are needed.
  3. Obtain read/browse access: If anonymous access is disabled, obtain or use an existing low-privilege account that has at least read/browse permissions on a Swift, Terraform, or Conda hosted repository.
  4. Craft upload request: Prepare a malicious artifact (e.g., a Terraform module, Swift package, or Conda package) and construct a multipart HTTP POST request targeting the component upload API endpoint: POST /service/rest/v1/components?repository=<target-repo>.
  5. Submit the upload: Send the crafted request with appropriate authentication headers (or none, if anonymous access is enabled). The missing authorization check allows the upload to succeed despite the absence of write permissions.
  6. Achieve supply chain impact: The malicious artifact is now available in the trusted repository. Downstream consumers pulling from this repository will receive the attacker-controlled content (Sonatype Advisory).

Indicators of compromise

  • Network: Unexpected POST /service/rest/v1/components requests to Nexus Repository 3 instances, particularly from accounts or IP addresses not normally associated with artifact publishing; requests targeting Swift, Terraform, or Conda hosted repositories.
  • Logs: Nexus audit logs showing POST /service/rest/v1/components events attributed to accounts holding only read/browse roles on Swift, Terraform, or Conda repositories, or attributed to the anonymous principal; successful upload responses (HTTP 204) from such accounts.
  • File System / Repository: Unexpected or unrecognized artifacts appearing in Swift, Terraform, or Conda hosted repositories that were not published through normal CI/CD pipelines or authorized workflows.
  • Process/Behavior: Downstream build failures or unexpected dependency resolutions following unauthorized artifact uploads; alerts from Repository Firewall or IQ Server on newly introduced components in affected repositories (Sonatype Advisory).

Mitigation and workarounds

Sonatype recommends upgrading all affected Nexus Repository 3 CE/Pro instances to version 3.94.0 or later, which contains the fix for this vulnerability. For those unable to upgrade immediately, Sonatype recommends the following interim mitigations: (1) Review and revoke unnecessary read/browse role grants on Swift, Terraform, and Conda hosted repositories; (2) Set the repository write policy to DENY on affected hosted repositories to block all uploads; (3) If global anonymous access is enabled and not required, disable it via Administration > Security > Anonymous Access; (4) Monitor audit logs for unauthorized POST /service/rest/v1/components requests from low-privilege or anonymous accounts (Sonatype Advisory, Sonatype Release Notes).

Community reactions

The vulnerability was discovered and responsibly reported by security researcher muhammaddaffa through Sonatype's Bug Bounty Program, and Sonatype followed a responsible disclosure process by publishing a detailed advisory on the same day as the fix release. No significant broader media coverage or notable researcher commentary beyond the official advisory has been identified at this time (Sonatype Advisory).

Additional resources


SourceThis report was generated using AI

Related Sonatype Nexus 3 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17601HIGH8.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17603HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17600HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17599MEDIUM6.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17598MEDIUM5.3
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management