๐Ÿ” CVE Alert

CVE-2026-10748

UNKNOWN 0.0

Nexus Repository 3 - Remote Code Execution via License Deserialization

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.

CWE CWE-502
Vendor sonatype
Product nexus repository
Published Jun 16, 2026
Last Updated Jun 16, 2026
Stay Ahead of the Next One

Get instant alerts for sonatype nexus repository

Be the first to know when new unknown vulnerabilities affecting sonatype nexus repository are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Sonatype / Nexus Repository
3.0.0 < 3.92.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
help.sonatype.com: https://help.sonatype.com/en/sonatype-nexus-repository-3-92-0-release-notes.html support.sonatype.com: https://support.sonatype.com/hc/en-us/articles/52335766035603

Credits

Rahul Maini with Hacktron AI