PT-2026-49748 · Sonatype · Nexus Repository 3
CVE-2026-10748
·
Published
2026-06-16
·
Updated
2026-06-16
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Sonatype Nexus Repository 3 versions prior to 3.92.0
Description
An authenticated user possessing the
nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands with the permissions of the Nexus process user.Recommendations
Update to version 3.92.0 or later.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nexus Repository 3