Beveiligingsadvies

CVE-2026-14504

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-07-14 15:55:04
Laatst bijgewerkt 2026-07-15 14:10:02
Toegewezen door Sonatype
CVSS-score 8.2
Status PUBLISHED

Beschrijving

An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform, or Conda hosted repository to upload arbitrary artifacts, bypassing the intended write-permission check.