
Happy to share that my first CVE is now public: CVE-2026-5189 This allowed an attacker to gain unauthorized read/write access to the internal database and execute arbitrary OS commands. 🔗 Public Advisory: https://support.sonatype.com/hc/en-us/articles/50817138825491-CVE-2026-5189-Nexus-Repository-3-Hardcoded-Credential-in-Internal-Database-Component-2026-04-15 #bugbounty https://t.co/LmL0JACWzY
Post summary
The tweet announces CVE‑2026‑5189, a vulnerability in Nexus Repository 3 that permits attackers to read/write the internal database and execute arbitrary OS commands, and links to a public advisory for details.




