CVE-2026-5189Disclosure(sonatype / nexus_repository_manager)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch sonatype nexus_repository_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-798

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nexus_repository_manager

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-04-16)
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
nexus_repository_manager

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-15: 1Mentions · 2026-04-16: 4Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-16: 404-1504-16
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-151
Disclosure1
2026-04-164
Disclosure2General1Patch1
Full discourse5 posts
  • Shreyas Chavhan@shreyas_chavhan
    Disclosure

    Happy to share that my first CVE is now public: CVE-2026-5189 This allowed an attacker to gain unauthorized read/write access to the internal database and execute arbitrary OS commands. 🔗 Public Advisory: https://support.sonatype.com/hc/en-us/articles/50817138825491-CVE-2026-5189-Nexus-Repository-3-Hardcoded-Credential-in-Internal-Database-Component-2026-04-15 #bugbounty https://t.co/LmL0JACWzY

    Post summary

    The tweet announces CVE‑2026‑5189, a vulnerability in Nexus Repository 3 that permits attackers to read/write the internal database and execute arbitrary OS commands, and links to a public advisory for details.

    850220497.3K
    5.9K followersView on X
  • VulnTracker@vuln_tracker
    General

    @shreyas_chavhan Huge congrats on your first CVE! 🎉 CVE-2026-5189 is a serious find - unauthorized DB access + arbitrary OS command execution is no small thing. That’s impactful research right there. Love seeing high-quality, methodical work like this getting recognized. http://Vulntracker.io

    Post summary

    The tweet acknowledges the discovery of CVE‑2026‑5189, highlighting its severity with basic technical details, but provides no actionable information like PoC, exploit, or mitigation.

    020103835
    672 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Sonatype Nexus Repository (CVE-2026-5189) faces a critical 9.2 CVSS flaw. A hardcoded database credential grants full host access. Patch to v3.71.0 now! #NexusRepository #Sonatype #CyberSecurity #SupplyChain #DevSecOps #CVE20265189 #InfoSec https://securityonline.info/nexus-repository-hardcoded-credential-vulnerability-cve-2026-5189/ https://t.co/o5Hbo190UM

    Post summary

    The tweet highlights the CVE-2026-5189 hardcoded credential flaw in Sonatype Nexus Repository, notes its critical severity, and announces that a patch is available in version 3.71.0.

    00011276
    11.2K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-5189: Nexus Reposito... Hardcoded creds in OrientDB listener = instant root on any Nexus with binaryListenerEnabled—check your configs NOW. #nexus #hardcodedcreds. https://zerodaysignal.com/vulnerability/CVE-2026-5189 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-5189, highlighting hardcoded credentials in an OrientDB listener that provide root access when binaryListenerEnabled, and urges users to review configurations promptly.

    0000178
    218 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5189 CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain… https://www.cve.org/CVERecord?id=CVE-2026-5189

    Post summary

    The text details CVE-2026-5189 as a hard‑coded credentials flaw in Sonatype Nexus Repository Manager, outlining affected versions and attack vector, but provides no PoC, exploit, or patch information.

    0000071
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsonatypenexus_repository_manager---

Explore more