These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability was identified in Sonatype Nexus Repository 3, where two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. This could result in unauthorized modification of blobstore configuration without administrator approval. The vulnerability allows users with only the nexus:blobstores:create permission to convert an existing blobstore into a gro [truncated]
CVE-2026-77124 is a high-severity vulnerability in Sonatype Nexus Repository 3, with a CVSS score of 7.5. The vulnerability allows an account with script-execution permission to run previously created scripts even after an administrator has set nexus.scripts.allowCreation=false. This undermines the expectation that this setting fully blocks script execution.
CVE-2026-77123 debrief based on CVE Program and NVD records. A sensitive information disclosure vulnerability exists in Nexus Repository 3's capability read API. Users with the nexus:capabilities:read privilege can retrieve plaintext shared secrets from webhook capabilities, which should be masked. Affected versions are 3.2.0 through 3.95.x; version 3.96.0 fixes the issue.
An authorization flaw in the REST API repository details endpoint in Sonatype Nexus Repository 3 allows an account with read or browse permission on a group repository to retrieve metadata for member repositories without direct permission. This includes the anonymous user if granted this permission. For proxy repositories, disclosed metadata may reveal internal upstream hostnames.
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T17:17:01.250Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API, allowing a user with nx-datastores-update permission t [truncated]
The CVE-2026-17601 vulnerability allows a user with permission to update privilege definitions to modify a wildcard privilege assigned to their role, potentially granting broader permissions, including full administrative access, without additional authorization checks. This issue affects organizations using the impacted product, particularly those with high-security requirements. The vulnerability has a [truncated]
The CVE-2026-17600 vulnerability in Sonatype Nexus Repository 3 allows users with deleted, deactivated, or password-changed accounts to continue using their existing sessions, potentially leading to unauthorized access to repository content. This issue is particularly concerning for organizations with high-security requirements or sensitive repository content. The vulnerability was published on 2026-08-07 [truncated]
Sonatype Nexus Repository 3 contains a vulnerability where it did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. This oversight allows an account with permission to create at least one scheduled task type to supply a crafted property value that could cause the system to overwrite the configuration [truncated]
The CVE-2026-17597 vulnerability is a Server-Side Request Forgery (SSRF) issue in the email configuration verification feature of Nexus Repository 3. An attacker with the nexus:settings:update permission can submit arbitrary host and port values to the email test/verification endpoint, potentially allowing them to infer whether internal hosts and ports are reachable. This issue affects Nexus Repository 3 [truncated]
A stored cross-site scripting (XSS) vulnerability was found in Nexus Repository 3, which could allow a user with specific permissions to execute malicious script content in the browser of another user. This issue has been fixed in version 3.95.0. The vulnerability was found in Nexus Repository 3, with a CVSS score of 6.3 and MEDIUM severity. The issue has been fixed in version 3.95.0. A user with the nexu [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-07T17:16:59.470Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This incorrect authorization vulnerability (CWE-863) in Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x allows a user with delegated repository-admin privilege scoped to a specific repository [truncated]
CVE-2026-14644 is a high-severity privilege escalation vulnerability in Nexus Repository 3's REST privileges API. An authenticated user with permission to manage privileges could escalate their access to full administrator under certain role configurations by exploiting a type-confusion flaw in the privilege update endpoint. Sonatype has released a patch in version 3.95.0. Defenders should assess exposure [truncated]
A vulnerability in Nexus Repository 3 allows users with read access to a proxy repository to potentially expose sensitive information, such as cloud IAM credentials, if the upstream server is compromised or controlled by an attacker. This occurs because the existing Server-Side Request Forgery (SSRF) protections are not applied to HTTP redirect targets returned by proxy repository upstream servers.
A Server-Side Request Forgery (SSRF) vulnerability exists in Nexus Repository 3 due to insufficient validation of the 'Webhook: Global' capability's configured URL, allowing users with Capability Administration permission to cause the server to send requests to internal network locations. This permission can be granted by role assignment, independent of authentication status.
A Server-Side Request Forgery (SSRF) vulnerability exists in Nexus Repository 3 due to improper validation of SSL certificate retrieval requests. This issue allows users with the nexus:ssl-truststore:read permission to cause the server to initiate outbound connections to internal or restricted network hosts. The vulnerability affects Nexus Repository 3.0.0 through versions prior to 3.94.0. Defenders shoul [truncated]
CVE-2026-14504 is an authorization bypass vulnerability in Sonatype's Nexus Repository 3, specifically affecting the component upload API for Swift, Terraform, or Conda hosted repositories. This vulnerability allows users with only read/browse privileges to upload arbitrary artifacts, effectively bypassing intended write-permission checks. The vulnerability has a CVSS score of 8.2, indicating high severit [truncated]
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. The vulnerability exists when a format-specific API key realm is enabled and the targeted user has an active API key. Defenders should assess exposure and prioritize securing API keys, especially for format-specific r [truncated]
A medium-severity authorization vulnerability (CVSS Score: 5.9) was discovered in Sonatype Nexus Repository Manager before version 3.93.0. The vulnerability allows a delegated repository administrator to disclose stored upstream proxy credentials through the proxy repository configuration. This issue was publicly disclosed on June 17, 2026. Organizations using affected versions of Sonatype Nexus Repositor [truncated]
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0. This high-severity vulnerability allows attackers to execute arbitrary OS commands, potentially leading to lateral movement or privilege escalation, and risk of unauthorized a [truncated]
CVE-2026-3329 is a HIGH severity vulnerability with a CVSS score of 8.7. A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints. The CVE was published on 2026-06-11T18:16:25.343Z and last modified on 2026-06-11T21:02:42.240Z.
An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via the HTML index page in Sonatype Nexus Repository versions 3.6.0 through versions before 3.92.0. This vulnerability allows attackers to perform actions in the context of the victim's session, potentially leadin [truncated]
CVE-2026-5189 is a critical vulnerability in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5, allowing unauthenticated attackers with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. This requires the non-default configuration 'nexus.orient.binaryListenerEnabled=true' to be enabled.
A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2. This vulnerability allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction. The vulnerability has a CVSS score of 5.1 and is classified as MEDIUM severity. The CVE record was published [truncated]
CVE-2019-7238 concerns an incorrect access control vulnerability in Sonatype Nexus Repository Manager. It is listed in CISA’s Known Exploited Vulnerabilities catalog, which means it should be treated as a high-priority remediation item. The supplied official sources do not provide version ranges or deeper technical detail, so the safest response is to follow vendor update guidance and confirm the affected [truncated]
CVE-2020-10199 is a Sonatype Nexus Repository remote code execution vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2021-11-03. The official guidance in the supplied corpus is to apply updates per vendor instructions, making this an urgent patching item for any affected deployment.