MEDIUM

CVE-2026-10741

2026-06-17 CVSS v4.0
CVSS
5.9

Description

Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.

Summary dbcve.org

Sonatype Nexus Repository Manager before version 3.93.0 has an authorization flaw in the proxy repository configuration that permits a delegated repository administrator to access and disclose upstream proxy credentials that should be restricted from their view.

Mitigation

Upgrade Sonatype Nexus Repository Manager to version 3.93.0 or later to remediate the authorization bypass. Review existing delegated administrator permissions and rotate any exposed credentials as a precaution.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.27%
Probability of exploitation in next 30 days
19.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE