CVE-2026-14644
Nexus Repository 3 - Privilege Escalation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint.
| CWE | CWE-843 |
| Vendor | sonatype |
| Product | nexus repository 3 |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for sonatype nexus repository 3
Be the first to know when new unknown vulnerabilities affecting sonatype nexus repository 3 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Sonatype / Nexus Repository 3
3.19.0 < 3.95.0
References
Credits
Mayur Udiniya aka roughwire (https://x.com/roughwire/)