Sonatype Nexus Repository Manager — known CVE vulnerabilities
Every CVE whose affected-product data names Sonatype Nexus Repository Manager, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVE-2019-9629 — CVSS 9.8 (critical): Sonatype Nexus Repository Manager before 3.17.0 establishes a default administrator user with weak defaults (fixed credentials).
CVE-2017-17717 — CVSS 9.8 (critical): Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration…
CVE-2026-5189 — CVSS 9.8 (critical): CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated…
CVE-2026-3199 — CVSS 8.8 (high): A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated…
CVE-2026-17600 — CVSS 8.8 (high): Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's…
CVE-2019-5475 — CVSS 8.8 (high): The Nexus Yum Repository Plugin in v2 is vulnerable to Remote Code Execution when instances using CommandLineExecutor.java are supplied…
CVE-2020-11753 — CVSS 8.8 (high): An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0. It is possible for a user with appropriate…
CVE-2026-17603 — CVSS 8.8 (high): Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration…
CVE-2020-15012 — CVSS 8.6 (high): A Directory Traversal issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.19. A user that requests a crafted path can…
CVE-2021-40143 — CVSS 8.2 (high): Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection. By sending a crafted HTTP request, a remote…
CVE-2026-14646 — CVSS 7.7 (high): Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy…
CVE-2019-9630 — CVSS 7.5 (high): Sonatype Nexus Repository Manager before 3.17.0 has a weak default of giving any unauthenticated user read permissions on the repository…
CVE-2026-11403 — CVSS 7.5 (high): A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized…
CVE-2026-3329 — CVSS 7.5 (high): A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via…
CVE-2026-17599 — CVSS 7.2 (high): Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not…
CVE-2019-15588 — CVSS 7.2 (high): There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code…
CVE-2019-16530 — CVSS 7.2 (high): Sonatype Nexus Repository Manager 2.x before 2.14.15 and 3.x before 3.19, and IQ Server before 72, has remote code execution.
CVE-2026-77124 — CVSS 7.2 (high): In affected versions of Nexus Repository 3, the script execution endpoint (POST /service/rest/v1/script/{name}/run) did not verify whether…
CVE-2026-17601 — CVSS 7.2 (high): A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant…
CVE-2026-10748 — CVSS 7.2 (high): An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating…
CVE-2026-14644 — CVSS 7.2 (high): Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. An authenticated user with permission to…
CVE-2026-17593 — CVSS 7.2 (high): An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy…
CVE-2026-77125 — CVSS 7.1 (high): A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly…
CVE-2020-29436 — CVSS 6.5 (medium): Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content…
CVE-2024-5764 — CVSS 6.5 (medium): Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in the code responsible for encrypting any…
CVE-2026-14504 — CVSS 6.5 (medium): An authorization bypass in Nexus Repository 3's component upload API allowed a user with only read/browse privileges on a Swift, Terraform…
CVE-2026-77123 — CVSS 6.5 (medium): Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the…
CVE-2026-77121 — CVSS 6.5 (medium): A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an oversized metadata…
CVE-2021-29159 — CVSS 6.1 (medium): A cross-site scripting (XSS) vulnerability has been discovered in Nexus Repository Manager 3.x before 3.30.1. An attacker with a local…
CVE-2026-17596 — CVSS 6.1 (medium): Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or…
CVE-2026-14645 — CVSS 5.5 (medium): Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP…
CVE-2021-37152 — CVSS 5.4 (medium): Multiple XSS issues exist in Sonatype Nexus Repository Manager 3 before 3.33.0. An authenticated attacker with the ability to add HTML…
CVE-2026-7308 — CVSS 5.4 (medium): An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the…
CVE-2021-30635 — CVSS 5.3 (medium): Sonatype Nexus Repository Manager 3.x before 3.30.1 allows a remote attacker to get a list of files and directories that exist in a…
CVE-2026-7494 — CVSS 5.0 (medium): Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the…
CVE-2026-10741 — CVSS 4.9 (medium): Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a…
CVE-2020-11415 — CVSS 4.9 (medium): An issue was discovered in Sonatype Nexus Repository Manager 2.x before 2.14.17 and 3.x before 3.22.1. Admin users can retrieve the LDAP…
CVE-2026-17598 — CVSS 4.9 (medium): Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or…
CVE-2026-17594 — CVSS 4.9 (medium): Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the…
CVE-2018-12100 — CVSS 4.8 (medium): Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.
CVE-2021-42568 — CVSS 4.3 (medium): Sonatype Nexus Repository Manager 3.x through 3.35.0 allows attackers to access the SSL Certificates Loading function via a low-privileged…
CVE-2021-43293 — CVSS 4.3 (medium): Sonatype Nexus Repository Manager 3.x before 3.36.0 allows a remote authenticated attacker to potentially perform network enumeration via…
CVE-2021-34553 — CVSS 4.3 (medium): Sonatype Nexus Repository Manager 3.x before 3.31.0 allows a remote authenticated attacker to get a list of blob files and read the content…
CVE-2026-77122 — CVSS 4.3 (medium): An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus…
CVE-2026-3048 — CVSS 3.8 (low): An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1…
CVE-2026-17595 — CVSS 2.7 (low): Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create…
CVE-2026-17597 — CVSS 2.7 (low): Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature. A user…