Executive brief
Sonatype Nexus Repository Manager, a tool used by software development teams to store and manage their code packages, contains a security flaw in how it generates certain API keys. An attacker could potentially predict or obtain these keys to gain unauthorized access to repository operations, acting as a legitimate user. This could lead to the unauthorized viewing or downloading of private software components and intellectual property.
Technical details
An insufficient entropy vulnerability (CWE-331) exists in the format-specific API key generation process of Sonatype Nexus Repository Manager. The flaw affects NuGet API Keys, Docker Bearer Tokens, and npm Bearer Tokens. A remote, unauthenticated attacker can exploit this to gain unauthorized access to repository operations, provided the specific API key realm is enabled and the target user has an active key. The vulnerability is addressed in version 3.93.0.
Affected products
- Sonatype Nexus Repository Manager 3.0.0 up to 3.92.3
Timeline
- 2026-07-14: advisory: Initial disclosure by Sonatype and NVD publication.
- 2026-07-14: patched: Fixed in Sonatype Nexus Repository 3.93.0.