PatchSiren cyber security CVE debrief
CVE-2026-10741 Sonatype CVE debrief
A medium-severity authorization vulnerability (CVSS Score: 5.9) was discovered in Sonatype Nexus Repository Manager before version 3.93.0. The vulnerability allows a delegated repository administrator to disclose stored upstream proxy credentials through the proxy repository configuration. This issue was publicly disclosed on June 17, 2026. Organizations using affected versions of Sonatype Nexus Repository Manager should prioritize upgrading to version 3.93.0 or later to mitigate this vulnerability. The CVE record and NVD detail provide additional information on this vulnerability.
- Vendor
- Sonatype
- Product
- Nexus Repository Manager
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-23
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-23
Who should care
Administrators and security teams responsible for Sonatype Nexus Repository Manager instances, especially those with delegated repository administrators, should be aware of this vulnerability and take immediate action to upgrade to a patched version.
Technical summary
The vulnerability (CVE-2026-10741) is an authorization issue in the proxy repository configuration of Sonatype Nexus Repository Manager before 3.93.0. It enables a delegated repository administrator to access and disclose stored upstream proxy credentials. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 5.9, indicating a medium severity level. The vulnerability is classified under CWE-863.
Defensive priority
High
Recommended defensive actions
- Upgrade Sonatype Nexus Repository Manager to version 3.93.0 or later.
- Review and restrict permissions for delegated repository administrators.
- Monitor for any suspicious activity related to proxy repository configurations.
- Implement additional security measures, such as multi-factor authentication for administrators.
- Regularly review and update credentials stored in the repository manager.
- Consider implementing a Web Application Firewall (WAF) to detect and prevent exploitation attempts.
- Keep the repository manager and its dependencies up-to-date with the latest security patches.
Evidence notes
The information provided is based on the CVE record and NVD detail for CVE-2026-10741. The vulnerability was publicly disclosed on June 17, 2026. The accuracy of this information relies on the data provided by these sources.
Official resources
-
CVE-2026-10741 CVE record
CVE.org
-
CVE-2026-10741 NVD detail
NVD
-
Source item URL
nvd_modified
-
Source reference
103e4ec9-0a87-450b-af77-479448ddef11
-
Source reference
103e4ec9-0a87-450b-af77-479448ddef11
Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.