Junglewise Threat Intelligence

CVE-2026-3199: Sonatype Nexus Repository RCE in task management component

CVE-2026-3199 · Severity: info · CVSS 9.4 · Published 2026-04-08

Technologies: Sonatype Nexus Repository. Vendors: Sonatype.

Executive brief

Sonatype Nexus Repository is a software platform used by organizations to store and manage their software components and dependencies. A security vulnerability in its task management system allows an authorized user with basic task-creation permissions to run unauthorized commands on the server. This could lead to a complete takeover of the repository, potentially allowing an attacker to steal proprietary code or disrupt software delivery pipelines.

Technical details

A deserialization of untrusted data vulnerability (CWE-502) exists in the task management component of Sonatype Nexus Repository. Authenticated attackers with permissions to create tasks can exploit this flaw to bypass the 'nexus.scripts.allowCreation' security control, which is intended to restrict script execution. By submitting a specially crafted task, an attacker can achieve remote code execution (RCE) on the underlying server. The vulnerability affects versions 3.22.1 through 3.90.2 and is addressed in version 3.91.0.

Affected products

  • Sonatype Nexus Repository 3.22.1 through 3.90.2

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched: Fixed in version 3.91.0

References

Related threats