PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77122 Sonatype CVE debrief

An authorization flaw in the REST API repository details endpoint in Sonatype Nexus Repository 3 allows an account with read or browse permission on a group repository to retrieve metadata for member repositories without direct permission. This includes the anonymous user if granted this permission. For proxy repositories, disclosed metadata may reveal internal upstream hostnames.

Vendor
Sonatype
Product
Nexus Repository Manager
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-22
Advisory published
2026-09-02
Advisory updated
2026-09-22

Who should care

Defenders and administrators of Sonatype Nexus Repository 3 installations should assess exposure and implement compensating controls. This includes verifying affected versions, reviewing repository configurations, and monitoring for potential misuse.

Why it matters

CVE-2026-77122 is a medium-severity vulnerability in Sonatype Nexus Repository 3 that allows accounts with limited permissions to retrieve metadata for repositories without direct access. Defenders should verify affected versions, assess exposure, and implement compensating controls to limit potential metadata exposure and prevent unauthorized access.

  • Potential metadata exposure for member repositories
  • Possible revelation of internal upstream hostnames for proxy repositories
  • Need for verification of affected versions and configurations
  • Prioritization of compensating controls and monitoring

Technical summary

The REST API repository details endpoint in Sonatype Nexus Repository 3 has an authorization flaw. Accounts with read or browse permission on a group repository can retrieve metadata for member repositories without direct permission. Disclosed metadata may include configured remote URLs for proxy repositories, potentially revealing internal upstream hostnames. This vulnerability allows accounts with limited permissions to retrieve metadata for repositories without direct access. Defenders should verify affected versions, assess exposure, and implement compensating controls to limit potential metadata exposure and prevent unauthorized access.

Defensive priority

Defenders should prioritize verifying affected versions, assessing exposure, and implementing compensating controls.

Recommended defensive actions

  • Verify if the installed version of Sonatype Nexus Repository 3 is affected
  • Assess exposure based on repository configurations and user permissions
  • Implement compensating controls to limit metadata exposure
  • Monitor for potential misuse of the REST API endpoint
  • Review repository configurations for potential exposure
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the authorization flaw in Sonatype Nexus Repository 3. The flaw allows accounts with read or browse permission on a group repository to retrieve metadata for member repositories without direct permission.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77122 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77122

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77122 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77122

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://help.sonatype.com/en/sonatype-nexus-repository-3-96-0-release-notes.html

    103e4ec9-0a87-450b-af77-479448ddef11 - Release Notes

  • Source reference

    Unverified legacy reference

    URL: https://support.sonatype.com/hc/en-us/articles/54637328224019/

    103e4ec9-0a87-450b-af77-479448ddef11 - Mitigation, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.