logo

Critical Hardcoded Credential Bug Hits Nexus Repository 3

ID: 0531f968-f7c6-58c9-9a2e-b11e43b254d4

STIX ID: report--0531f968-f7c6-58c9-9a2e-b11e43b254d4

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-16

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-5189, CVSS 9.2) was disclosed in Sonatype Nexus Repository 3: a hardcoded credential in the OrientDB binary listener could allow unauthenticated attackers to access the internal database and execute commands on the host. The issue affects Nexus Repository 3.x up to 3.70.5, is fixed in 3.71.0, and is only exploitable if the non-default setting `nexus.orient.binaryListenerEnabled=true` has been enabled; administrators should check and remove this setting if not needed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.