PatchSiren cyber security CVE debrief
CVE-2026-77122 Sonatype CVE debrief
An authorization flaw in the REST API repository details endpoint in Sonatype Nexus Repository 3 allows an account with read or browse permission on a group repository to retrieve metadata for member repositories without direct permission. This includes the anonymous user if granted this permission. For proxy repositories, disclosed metadata may reveal internal upstream hostnames.
- Vendor
- Sonatype
- Product
- Nexus Repository Manager
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-22
Who should care
Defenders and administrators of Sonatype Nexus Repository 3 installations should assess exposure and implement compensating controls. This includes verifying affected versions, reviewing repository configurations, and monitoring for potential misuse.
Why it matters
CVE-2026-77122 is a medium-severity vulnerability in Sonatype Nexus Repository 3 that allows accounts with limited permissions to retrieve metadata for repositories without direct access. Defenders should verify affected versions, assess exposure, and implement compensating controls to limit potential metadata exposure and prevent unauthorized access.
- Potential metadata exposure for member repositories
- Possible revelation of internal upstream hostnames for proxy repositories
- Need for verification of affected versions and configurations
- Prioritization of compensating controls and monitoring
Technical summary
The REST API repository details endpoint in Sonatype Nexus Repository 3 has an authorization flaw. Accounts with read or browse permission on a group repository can retrieve metadata for member repositories without direct permission. Disclosed metadata may include configured remote URLs for proxy repositories, potentially revealing internal upstream hostnames. This vulnerability allows accounts with limited permissions to retrieve metadata for repositories without direct access. Defenders should verify affected versions, assess exposure, and implement compensating controls to limit potential metadata exposure and prevent unauthorized access.
Defensive priority
Defenders should prioritize verifying affected versions, assessing exposure, and implementing compensating controls.
Recommended defensive actions
- Verify if the installed version of Sonatype Nexus Repository 3 is affected
- Assess exposure based on repository configurations and user permissions
- Implement compensating controls to limit metadata exposure
- Monitor for potential misuse of the REST API endpoint
- Review repository configurations for potential exposure
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the authorization flaw in Sonatype Nexus Repository 3. The flaw allows accounts with read or browse permission on a group repository to retrieve metadata for member repositories without direct permission.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77122 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77122
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77122 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77122
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://help.sonatype.com/en/sonatype-nexus-repository-3-96-0-release-notes.html
103e4ec9-0a87-450b-af77-479448ddef11 - Release Notes
-
Source reference
Unverified legacy reference
URL: https://support.sonatype.com/hc/en-us/articles/54637328224019/
103e4ec9-0a87-450b-af77-479448ddef11 - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.