What is CVE-2026-14644?
This CVE describes a privilege escalation vulnerability in the REST privileges API of Nexus Repository 3, caused by a type-confusion flaw. An authenticated user with permission to manage privileges could, under certain role configurations, escalate their own access to full administrator. Affected users should immediately apply the security update provided by the vendor.
Azərbaycanca: Bu CVE, Nexus Repository 3-də REST imtiyazlar API-sində 'type-confusion' zəifliyi vasitəsilə imtiyaz yüksəltmə (privilege escalation) qüsurudur. İmtiyazları idarə etmək icazəsi olan autentifikasiya olunmuş istifadəçi müəyyən rol konfiqurasiyalarında bu qüsurdan istifadə edərək öz girişini tam administrator səviyyəsinə yüksəldə bilər. Təsirə məruz qalan sistemlərin administratorları dərhal təchizatçı tərəfindən təqdim olunan təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Is authentication required to exploit the CVE-2026-14644 vulnerability?
Yes, the attacker must be an authenticated user in Nexus Repository 3 and have permission to manage privileges.
What is the potential impact of CVE-2026-14644?
Under certain role configurations, an attacker could escalate their access to full administrator level.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.