THREAT OPS › Threat News › [NVD] CVE-2026-14644 — Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw i
[NVD] CVE-2026-14644 — Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw i
CVE-2026-14644 CVSS: None Published: 2026-08-07T17:16:57.030
Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator by exploiting a type-confusion flaw in the privilege update endpoint.
Indicators of compromise
- CVE-2026-14644cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14644