CVE-2026-3199
🟡 Monitoruj
Wykonanie dowolnego kodu w Sonatype Nexus Repository umożliwia atakującemu z uprawnieniami do tworzenia zadań.
CVSS
8.8
EPSS
0.5%
Exploit
none
Vendor
sonatype
Opis źródłowy (NVD)
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.5% |
| Opublikowano (NVD) | 2026-04-08 23:16:59 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-18 16:11:14 UTC |
Referencje
- https://help.sonatype.com/en/sonatype-nexus-repository-3-91-0-release-notes.html (103e4ec9-0a87-450b-af77-479448ddef11) [Release Notes]
- https://support.sonatype.com/hc/en-us/articles/50615414548499 (103e4ec9-0a87-450b-af77-479448ddef11) [Vendor Advisory]