Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77122— Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repository Metadata via Group Repository Permissions

Quick assessment

Affected
Sonatype Nexus Repository 3
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Sonatype Nexus Repository Manager 3 的 REST API 仓库详情端点(GET /service/rest/v1/repositories/{repositoryName})存在一个授权缺陷:如果某个账户对某个组仓库拥有读取或浏览权限,那么该账户可以通过直接请求成员仓库的名称,获取其并未直接拥有权限的成员仓库的元数据。对于代理(proxy)仓库,披露的元数据中包含了配置中的远程 URL,这可能会暴露内部上游主机名。如果匿名用户被授予了此权限,匿名用户也包含在内;而匿名用户是否拥有

CVSS 5.3 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
Sonatype Nexus Repository 3 3.38.0< 3.96.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77122

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repository Metadata via Group Repository Permissions
Source: CVE Program / CVE List V5
Vulnerability Description
An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group repository to retrieve metadata for member repositories on which it held no direct permission, by requesting the endpoint directly for the member repository name. For proxy repositories, the disclosed metadata includes the configured remote URL, which may reveal internal upstream hostnames. This includes the anonymous user if it has been granted this permission; whether the anonymous user holds this permission depends on the role and permission configuration of the specific installation.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Sonatype Nexus Repository 3 3.38.0 ~ 3.96.0 cpe:2.3:a:sonatype:nexus_repository_manager:3.38.0:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-77122

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77122

登录查看更多情报信息。

Vendor Advisories for CVE-2026-77122 (1)

Vendor Pages for CVE-2026-77122 (1)

Same Patch Batch · Sonatype · 2026-09-02 · 5 CVEs total

CVE-2026-77124 7.5 HIGH Nexus Repository 3 - Script Execution Disable Setting Not Enforced
CVE-2026-77125 7.1 HIGH Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints
CVE-2026-77123 6.0 MEDIUM Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API
CVE-2026-77121 5.3 MEDIUM Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields

IV. Related Vulnerabilities

V. Comments for CVE-2026-77122

No comments yet


Leave a comment