PatchSiren cyber security CVE debrief
CVE-2026-77124 Sonatype CVE debrief
CVE-2026-77124 is a high-severity vulnerability in Sonatype Nexus Repository Manager 3, with a CVSS score of 7.5. The vulnerability occurs because the script execution endpoint did not verify whether script execution had been administratively disabled, allowing users with script-execution permission to run previously created scripts even after an administrator had set nexus.scripts.allowCreation=false. This issue affects versions from 3.21.2 up to but not including 3.96.0.
- Vendor
- Sonatype
- Product
- Nexus Repository Manager
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-02
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-02
- Advisory updated
- 2026-09-22
Who should care
Defenders and administrators of Sonatype Nexus Repository Manager 3 should assess exposure and verify their version, user permissions, and script execution settings to prevent unauthorized script execution. They need to prioritize verifying their Nexus Repository Manager version, checking for existing scripts that could be executed, reviewing user permissions, and ensuring that script execution is properly disabled if intended.
Why it matters
CVE-2026-77124 is a high-severity vulnerability in Sonatype Nexus Repository Manager 3 that allows users with script-execution permission to run scripts even when administratively set to disable script execution. Defenders should verify their version, review user permissions, and update if necessary to prevent unauthorized script execution.
- Defenders need to verify their Nexus Repository Manager version and check for existing scripts that could be executed
- Review user permissions to ensure script execution is properly disabled if intended
- Update to version 3.96.0 or later if vulnerable to prevent unauthorized script execution
Technical summary
The script execution endpoint in affected versions of Nexus Repository 3 did not verify whether script execution had been administratively disabled. This allowed users with script-execution permission to run previously created scripts even after an administrator set nexus.scripts.allowCreation=false. The issue affects versions from 3.21.2 up to but not including 3.96.0, and defenders should assess exposure and verify their version, user permissions, and script execution settings to prevent unauthorized script execution.
Defensive priority
Defenders should prioritize verifying their Nexus Repository Manager version and checking for any existing scripts that could be executed. They should also review user permissions and ensure that script execution is properly disabled if intended.
Recommended defensive actions
- Verify Nexus Repository Manager version and check for existing scripts that could be executed
- Review user permissions and ensure script execution is properly disabled if intended
- Update to version 3.96.0 or later if vulnerable
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, its impact, and affected versions. However, additional information about potential exploitation or specific attacks is not available in the provided sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-77124 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-77124
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-77124 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77124
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://help.sonatype.com/en/sonatype-nexus-repository-3-96-0-release-notes.html
103e4ec9-0a87-450b-af77-479448ddef11 - Release Notes
-
Source reference
Unverified legacy reference
URL: https://support.sonatype.com/hc/en-us/articles/54641528273811/
103e4ec9-0a87-450b-af77-479448ddef11 - Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.