Script Execution Flaw in Nexus Repository 3 by Sonatype
CVE-2026-77124

7.5HIGH

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
2 September 2026

What is CVE-2026-77124?

In specific versions of Nexus Repository 3, a vulnerability allows execution of scripts through the script execution endpoint (POST /service/rest/v1/script/{name}/run) without verifying if script execution has been administratively disabled. This means that users with script-execution permissions can still run previously created scripts, circumventing the intended security measure where setting nexus.scripts.allowCreation to false should block all script execution. As a result, this vulnerability could pose a significant risk to the integrity and security of the system.

Affected Version(s)

Nexus Repository 3 3.21.2 < 3.96.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yousif (s3c_krd)
.