Junglewise Threat Intelligence

CVE-2026-77122: Sonatype Nexus Repository authorization bypass in REST API

CVE-2026-77122 · Severity: medium · CVSS 4.3 · Published 2026-09-02

Technologies: Sonatype Nexus Repository 3, Sonatype Nexus Repository Manager. Vendors: Sonatype.

Executive brief

Sonatype Nexus Repository is a software artifact repository manager used by organizations to store and manage build dependencies and application components. A flaw in its REST API allows users with read or browse permissions on a group repository to access metadata of private member repositories they shouldn't have access to, potentially exposing internal infrastructure hostnames and upstream server URLs. The vulnerability can be exploited by unauthenticated users if the anonymous user has been granted the necessary permissions.

Technical details

This is an authorization bypass vulnerability in the REST API endpoint GET /service/rest/v1/repositories/{repositoryName}. The vulnerable component fails to properly check permissions when responding to requests for repository details. An attacker with read or browse permissions on a group repository can query the endpoint directly for member repository names to retrieve metadata they should not access. For proxy repositories, this disclosure includes the configured remote URL, which may reveal internal upstream hostnames. The vulnerability affects Nexus Repository 3 and can be exploited unauthentically if the anonymous user holds group browse/read permissions. Patches are available in version 3.96.3 and later.

Affected products

  • Sonatype Nexus Repository 3 3.0 through 3.96.2

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: patched: Fixed in version 3.96.3

References

Related threats