THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-14644 — Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw i

[NVD] CVE-2026-14644 — Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw i

mednvdPublished 2026-08-07

CVE-2026-14644 CVSS: None Published: 2026-08-07T17:16:57.030

Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14644