PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-77124 Sonatype CVE debrief

CVE-2026-77124 is a high-severity vulnerability in Sonatype Nexus Repository Manager 3, with a CVSS score of 7.5. The vulnerability occurs because the script execution endpoint did not verify whether script execution had been administratively disabled, allowing users with script-execution permission to run previously created scripts even after an administrator had set nexus.scripts.allowCreation=false. This issue affects versions from 3.21.2 up to but not including 3.96.0.

Vendor
Sonatype
Product
Nexus Repository Manager
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-02
Original CVE updated
2026-09-22
Advisory published
2026-09-02
Advisory updated
2026-09-22

Who should care

Defenders and administrators of Sonatype Nexus Repository Manager 3 should assess exposure and verify their version, user permissions, and script execution settings to prevent unauthorized script execution. They need to prioritize verifying their Nexus Repository Manager version, checking for existing scripts that could be executed, reviewing user permissions, and ensuring that script execution is properly disabled if intended.

Why it matters

CVE-2026-77124 is a high-severity vulnerability in Sonatype Nexus Repository Manager 3 that allows users with script-execution permission to run scripts even when administratively set to disable script execution. Defenders should verify their version, review user permissions, and update if necessary to prevent unauthorized script execution.

  • Defenders need to verify their Nexus Repository Manager version and check for existing scripts that could be executed
  • Review user permissions to ensure script execution is properly disabled if intended
  • Update to version 3.96.0 or later if vulnerable to prevent unauthorized script execution

Technical summary

The script execution endpoint in affected versions of Nexus Repository 3 did not verify whether script execution had been administratively disabled. This allowed users with script-execution permission to run previously created scripts even after an administrator set nexus.scripts.allowCreation=false. The issue affects versions from 3.21.2 up to but not including 3.96.0, and defenders should assess exposure and verify their version, user permissions, and script execution settings to prevent unauthorized script execution.

Defensive priority

Defenders should prioritize verifying their Nexus Repository Manager version and checking for any existing scripts that could be executed. They should also review user permissions and ensure that script execution is properly disabled if intended.

Recommended defensive actions

  • Verify Nexus Repository Manager version and check for existing scripts that could be executed
  • Review user permissions and ensure script execution is properly disabled if intended
  • Update to version 3.96.0 or later if vulnerable
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, its impact, and affected versions. However, additional information about potential exploitation or specific attacks is not available in the provided sources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-77124 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-77124

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-77124 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-77124

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://help.sonatype.com/en/sonatype-nexus-repository-3-96-0-release-notes.html

    103e4ec9-0a87-450b-af77-479448ddef11 - Release Notes

  • Source reference

    Unverified legacy reference

    URL: https://support.sonatype.com/hc/en-us/articles/54641528273811/

    103e4ec9-0a87-450b-af77-479448ddef11 - Mitigation, Vendor Advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.