CVE-2026-3438Disclosure(sonatype / nexus_repository_manager)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nexus_repository_manager

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-08); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
nexus_repository_manager

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-08: 2Mentions · 2026-04-09: 1Technical Details · 2026-04-08: 2Technical Details · 2026-04-09: 104-0804-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-082
Disclosure2
2026-04-091
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3438 Reflected Cross-Site Scripting in Sonatype Nexus Repository 3.0.0 Through 3.90.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3438

    Post summary

    Highlights a newly disclosed reflected XSS vulnerability in Sonatype Nexus Repository versions 3.0.0‑3.90.2.

    0000056
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-3438 A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute… https://www.cve.org/CVERecord?id=CVE-2026-3438 ----- Traducción: CVE-2026-3438 Exi… http://infoflow.cloud`

    Post summary

    The post announces a reflected XSS vulnerability in Sonatype Nexus Repository (CVE-2026-3438) and provides basic impact details.

    0000036
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3438 A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute… https://www.cve.org/CVERecord?id=CVE-2026-3438

    Post summary

    The entry provides a disclosure of a reflected XSS flaw (CVE‑2026‑3438) affecting Sonatype Nexus Repository 3.x, detailing the vulnerability type and affected releases, but offers no PoC, exploit code, or mitigation information.

    00000203
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsonatypenexus_repository_manager---

Explore more