Critical Hardcoded Credential Bug Hits Nexus Repository 3
ID: 0531f968-f7c6-58c9-9a2e-b11e43b254d4
STIX ID: report--0531f968-f7c6-58c9-9a2e-b11e43b254d4
Feed Name: securityonline.info
A critical vulnerability (CVE-2026-5189, CVSS 9.2) was disclosed in Sonatype Nexus Repository 3: a hardcoded credential in the OrientDB binary listener could allow unauthenticated attackers to access the internal database and execute commands on the host. The issue affects Nexus Repository 3.x up to 3.70.5, is fixed in 3.71.0, and is only exploitable if the non-default setting `nexus.orient.binaryListenerEnabled=true` has been enabled; administrators should check and remove this setting if not needed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
