Authorization Flaw in Sonatype Nexus Repository 3
CVE-2026-77122
5.3MEDIUM
What is CVE-2026-77122?
An authorization flaw in the REST API of Sonatype Nexus Repository 3 allows users with read or browse permissions on group repositories to access metadata for member repositories without direct permissions. This vulnerability potentially discloses sensitive information, including the configured remote URLs of proxy repositories, which may expose internal hostnames. The issue can also impact anonymous users based on specific role and permission settings in the installation.
Affected Version(s)
Nexus Repository 3 3.38.0 < 3.96.0
