Description
An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.
Published: 2026-07-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Nexus Repository Manager 3 has a flaw in its component upload API that bypasses the intended write‑permission check. A user who only has read or browse privileges on a Swift, Terraform, or Conda hosted repository can inject arbitrary artifacts into the Authorization Bypass (CWE‑862), allowing an attacker to tamper with the contents of a repository, potentially distributing malicious or tampered code to downstream consumers. The integrity of the managed packages is compromised, and supply‑chain attacks become possible if attackers control the upload process.

Affected Systems

The vulnerability affects Sonatype Nexus Repository Manager 3, specifically versions ranging from 3.88.0 through 3.93.2 as enumerated in the CPE list. These versions build attack surface.

Risk and Exploitability

The CVSS score of 8.2 marks the flaw as a high‑severity issue. The EPSS score of less than 1% indicates that the likelihood of real‑world exploitation remains low at present, and the vulnerability is not currently catalogued in CISA’s KEV list. Still, the attack vector is straightforward: an authenticated HTTP request to the upload endpoint is sufficient, requiring only read or browse rights that are commonly granted. Once exploited, the attacker can place any artifact into the repository, subverting downstream builds or deployments.

Generated by OpenCVE AI on July 31, 2026 at 09:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Nexus Repository Manager to 3.94.0 or later, which contains the vendor’s fix.
  • If an upgrade is not yet possible, immediately remove or restrict read/browse permissions for users intended to accept uploads.
  • Consider implementing network segmentation or API gateway rules that block the upload endpoint from general user traffic until a patch is applied.

Generated by OpenCVE AI on July 31, 2026 at 09:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.
Title Nexus Repository 3 - Authorization Bypass in Component Upload API
First Time appeared Sonatype
Sonatype nexus Repository Manager
Weaknesses CWE-862
CPEs cpe:2.3:a:sonatype:nexus_repository_manager:3.88.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.89.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.90.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.90.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.90.2:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.90.3:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.90.4:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.91.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.91.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.92.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.92.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.92.2:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.92.3:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.93.0:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.93.1:*:*:*:*:*:*:*
cpe:2.3:a:sonatype:nexus_repository_manager:3.93.2:*:*:*:*:*:*:*
Vendors & Products Sonatype
Sonatype nexus Repository Manager
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Sonatype Nexus Repository Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: Sonatype

Published:

Updated: 2026-07-15T14:10:02.530Z

Reserved: 2026-07-02T18:20:34.196Z

Link: CVE-2026-14504

cve-icon Vulnrichment

Updated: 2026-07-15T14:09:56.858Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:00:05Z

Weaknesses