Sensitive Information Disclosure in Nexus Repository by Sonatype
CVE-2026-77123

6MEDIUM

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
2 September 2026

What is CVE-2026-77123?

A vulnerability in Nexus Repository 3 allows an account with the nexus:capabilities:read privilege to access the plaintext shared secret of a webhook capability through the capability read API. This sensitive information, which is meant to be masked in API responses, poses a significant security risk. The affected versions, ranging from 3.2.0 to 3.95.x, have been addressed in the release of version 3.96.0 to mitigate this issue.

Affected Version(s)

Nexus Repository 3 3.2.0 < 3.96.0

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Beni Saprulah (HackerOne: https://hackerone.com/bebensap, LinkedIn: https://www.linkedin.com/in/beni-saprulah)
.