Executive brief
Nexus Repository is a widely-used software component management system that allows organizations to manage and store software artifacts. A flaw in the script execution endpoint allows authenticated users with script-execution permissions to continue running previously-created scripts even after an administrator has disabled all script creation and execution, circumventing the security control intended to block this capability.
Technical details
The vulnerability is a privilege escalation flaw in the script execution endpoint (POST /service/rest/v1/script/{name}/run) of Nexus Repository 3. The endpoint fails to verify whether script execution has been administratively disabled via the nexus.scripts.allowCreation=false setting. An authenticated attacker with script-execution permission can invoke previously-created scripts after the administrator has disabled script execution, bypassing the intended security boundary. The attack requires a valid user account with script-execution role permissions and network access to the API endpoint. A patch is available in later versions of Nexus Repository 3.
Affected products
- Sonatype Nexus Repository 3 (prior to 3.96.0)
Timeline
- 2026-09-02: disclosed