PatchSiren cyber security CVE debrief
CVE-2026-77121 Sonatype CVE debrief
A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. Only the targeted repository is affected; other repositories and overall server health remain unaffected.
- Vendor
- Sonatype
- Product
- Nexus Repository Manager
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-29
Who should care
Defenders responsible for Nexus Repository Manager instances, especially those with users who have artifact deployment permissions, should assess exposure and prioritize mitigation.
Why it matters
This vulnerability allows a user with artifact deployment permissions to upload a malicious POM file, causing permanent failures in listing or browsing repository components. Defenders should prioritize verifying and mitigating this issue in their Nexus Repository Manager instances.
- Defenders must verify artifact deployment permissions and restrict them to only necessary users.
- Defenders should monitor repository component listings and browsing for errors.
- Defenders need to review and apply vendor-provided patches or updates.
Technical summary
A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata field. This causes future attempts to list or browse that repository's components to permanently fail until an administrator repairs the underlying data. The vulnerability affects only the targeted repository, with other repositories and overall server health remaining unaffected. Defenders should prioritize verifying and mitigating this issue in their Nexus Repository Manager instances, especially those with users who have artifact deployment permissions.
Defensive priority
Defenders should prioritize verifying and mitigating this issue in their Nexus Repository Manager instances, especially those with users who have artifact deployment permissions.
Recommended defensive actions
- Verify the Nexus Repository Manager instance for exposure to artifact deployment permissions
- Restrict artifact deployment permissions to only necessary users
- Monitor repository component listings and browsing for errors
- Review and apply vendor-provided patches or updates
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Review compensating controls for exposed systems while remediation is scheduled and verified
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, including its description, CVSS score, and affected versions. Defenders should verify artifact deployment permissions and restrict them to only necessary users. The CVE Program and NVD provide official records, while vendor advisories offer additional guidance. Evidence limits suggest focusing on confirmed affected scope and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77121 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77121
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77121 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77121
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html
103e4ec9-0a87-450b-af77-479448ddef11 - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://support.sonatype.com/hc/en-us/articles/54635665756691/
103e4ec9-0a87-450b-af77-479448ddef11 - Permissions Required, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.