MEDIUM
CVE-2026-10741
CVSS
5.9
Description
Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.
Summary dbcve.org
Sonatype Nexus Repository Manager before version 3.93.0 has an authorization flaw in the proxy repository configuration that permits a delegated repository administrator to access and disclose upstream proxy credentials that should be restricted from their view.
Mitigation
Upgrade Sonatype Nexus Repository Manager to version 3.93.0 or later to remediate the authorization bypass. Review existing delegated administrator permissions and rotate any exposed credentials as a precaution.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.27%
Probability of exploitation in next 30 days
19.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.