Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77125— Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints

Quick assessment

Affected
Sonatype Nexus Repository 3
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Sonatype Nexus Repository 3 中发现了一个漏洞,其涉及两个用于 blobstore 组管理的 REST API 端点未正确执行预期的授权检查。仅被授予 权限的用户可以调用这些端点,将现有的 blobstore 转换为组 blobstore,而该操作本应要求 权限。这可能导致未经管理员批准,即可对 blobstore 配置进行未授权修改。 权限是一种具名权限,必须由管理员显式授予,并非默认拥有。

CVSS 7.1 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Sonatype Nexus Repository 3 3.19.0< 3.96.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77125

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nexus Repository 3 - Incorrect Authorization on Blobstore Group Endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check. A user granted only the nexus:blobstores:create permission could invoke these endpoints to convert an existing blobstore into a group blobstore, an action that should require the nexus:blobstores:update permission instead. This could result in unauthorized modification of blobstore configuration without administrator approval. The nexus:blobstores:create permission is a named permission that must be explicitly granted by an administrator; it is not held by default.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Sonatype Nexus Repository 3 3.19.0 ~ 3.96.0 cpe:2.3:a:sonatype:nexus_repository_manager:3.19.0:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-77125

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77125

登录查看更多情报信息。

Vendor Advisories for CVE-2026-77125 (1)

Vendor Pages for CVE-2026-77125 (1)

Same Patch Batch · Sonatype · 2026-09-02 · 5 CVEs total

CVE-2026-77124 7.5 HIGH Nexus Repository 3 - Script Execution Disable Setting Not Enforced
CVE-2026-77123 6.0 MEDIUM Nexus Repository 3 - Webhook Secret Disclosure via Capability Read API
CVE-2026-77121 5.3 MEDIUM Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Fields
CVE-2026-77122 5.3 MEDIUM Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repository Metada

IV. Related Vulnerabilities

V. Comments for CVE-2026-77125

No comments yet


Leave a comment