CVE-2026-3199Disclosure(sonatype / nexus_repository_manager)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Patch sonatype nexus_repository_manager systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nexus_repository_manager

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 5 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-08); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
nexus_repository_manager

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-08: 3Mentions · 2026-06-11: 2PoC Mentioned / Linked · 2026-06-11: 2Active Exploitation · 2026-06-11: 1Patch / Workaround · 2026-06-11: 2Technical Details · 2026-04-08: 2Technical Details · 2026-06-11: 204-0806-11
Signal classification4 categories
Disclosure
240.0%
General
120.0%
Active Exploitation
120.0%
PoC
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-083
Disclosure2General1
2026-06-112
Active Exploitation1PoC1
Full discourse5 posts
  • Armadin@ArmadinSecurity
    PoC

    We found a Nexus instance on a client's external network running default creds, noticed CVE-2026-3199 had just dropped, and decided to dig in rather than move on. The NVD entry was wrong, no writeup existed, and the patch diff was 52k lines. Used an LLM to triage it and had confirmed RCE in under two hours. Full kill chain + defensive guidance here: https://www.armadin.com/blog-posts/writeup-to-weaponization-cve-2026-3199-llm-assisted-rce-exploitation

    Post summary

    Discovered a Nexus instance with default credentials, confirmed CVE‑2026‑3199 allows RCE in under two hours, and provided a blog post detailing the kill chain and defensive guidance.

    0411121.8K
    462 followersView on X
  • jdelta@jdelta11
    Active Exploitation

    Recently I found an exposed default Sonatype Nexus Repository instance that was vulnerable to CVE-2026-3199. LLM performed a patch diff and found the four line fix within a squashed commit that had 52,000 lines changed - full RCE in under 2 hours. Blog: https://www.armadin.com/blog-posts/writeup-to-weaponization-cve-2026-3199-llm-assisted-rce-exploitation

    Post summary

    The post documents an exposed Sonatype Nexus instance that was successfully leveraged for a full RCE within two hours, includes a link to a detailed blog writeup, and mentions a concise patch fix.

    03052800
    685 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3199 A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permiss… https://www.cve.org/CVERecord?id=CVE-2026-3199 ----- Traducción: CVE-2026-3199 Una… http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑3199, providing affected versions and a brief impact description, without mentioning patches, PoC, exploit code, or active exploitation.

    0000056
    67 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3199 A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permiss… https://www.cve.org/CVERecord?id=CVE-2026-3199

    Post summary

    The text provides a brief disclosure that CVE‑2026‑3199 affects Sonatype Nexus Repository, allowing authenticated users to create tasks, but lacks further technical, exploit, or patch details.

    00000279
    57.0K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-3199: Nexus Repository 3 - Authenticate... Task property injection bypasses nexus.scripts.allowCreation - any authenticated user can now own your entire artifact r... https://zerodaysignal.com/vulnerability/CVE-2026-3199 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the discovery of CVE-2026-3199, a Nexus Repository 3 vulnerability that lets any authenticated user inject a task property to bypass nexus.scripts.allowCreation, thereby gaining ownership of artifacts.

    0000077
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsonatypenexus_repository_manager---

Explore more