PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-10741 Sonatype CVE debrief

A medium-severity authorization vulnerability (CVSS Score: 5.9) was discovered in Sonatype Nexus Repository Manager before version 3.93.0. The vulnerability allows a delegated repository administrator to disclose stored upstream proxy credentials through the proxy repository configuration. This issue was publicly disclosed on June 17, 2026. Organizations using affected versions of Sonatype Nexus Repository Manager should prioritize upgrading to version 3.93.0 or later to mitigate this vulnerability. The CVE record and NVD detail provide additional information on this vulnerability.

Vendor
Sonatype
Product
Nexus Repository Manager
CVSS
MEDIUM 5.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-07-21
Advisory published
2026-06-17
Advisory updated
2026-07-21

Who should care

Administrators and security teams responsible for Sonatype Nexus Repository Manager instances, especially those with delegated repository administrators, should be aware of this vulnerability and take immediate action to upgrade to a patched version.

Technical summary

The vulnerability (CVE-2026-10741) is an authorization issue in the proxy repository configuration of Sonatype Nexus Repository Manager before 3.93.0. It enables a delegated repository administrator to access and disclose stored upstream proxy credentials. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 5.9, indicating a medium severity level. The vulnerability is classified under CWE-863.

Defensive priority

High

Recommended defensive actions

  • Upgrade Sonatype Nexus Repository Manager to version 3.93.0 or later.
  • Review and restrict permissions for delegated repository administrators.
  • Monitor for any suspicious activity related to proxy repository configurations.
  • Implement additional security measures, such as multi-factor authentication for administrators.
  • Regularly review and update credentials stored in the repository manager.
  • Consider implementing a Web Application Firewall (WAF) to detect and prevent exploitation attempts.
  • Keep the repository manager and its dependencies up-to-date with the latest security patches.

Evidence notes

The information provided is based on the CVE record and NVD detail for CVE-2026-10741. The vulnerability was publicly disclosed on June 17, 2026. The accuracy of this information relies on the data provided by these sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-10741 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-10741

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-10741 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10741

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://help.sonatype.com/en/sonatype-nexus-repository-3-93-0-release-notes.html

    103e4ec9-0a87-450b-af77-479448ddef11

  • Source reference

    Unverified legacy reference

    URL: https://support.sonatype.com/hc/en-us/articles/52341191736851

    103e4ec9-0a87-450b-af77-479448ddef11

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.