Junglewise Threat Intelligence

CVE-2026-10741: Sonatype Nexus Repository Manager authorization bypass in proxy configuration

CVE-2026-10741 · Severity: info · CVSS 5.9 · Published 2026-06-17

Technologies: Sonatype Nexus Repository Manager. Vendors: Sonatype.

Executive brief

Sonatype Nexus Repository Manager, a tool used by software developers to store and manage software components, contains a security flaw in its proxy repository settings. This vulnerability allows a user with administrative access to a specific repository to view sensitive login credentials for external servers. If exploited, this could lead to unauthorized access to other systems within the organization's software supply chain.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Sonatype Nexus Repository Manager versions prior to 3.93.0. The flaw is located within the proxy repository configuration component. A remote attacker with high privileges (specifically a delegated repository administrator) can exploit this vulnerability to disclose stored credentials used for upstream proxy authentication. The attack requires network access to the management interface and specific administrative permissions. The issue is resolved in version 3.93.0.

Affected products

  • Sonatype Nexus Repository Manager before 3.93.0

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats