- CVE ID
- CVE-2026-5189
- CVE Description
- CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.
- Published
- Apr 1, 2026
- CVSS Score & Severity
9.2Critical
- CVSS Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS Score
- 0.036%
- KEV Status
Not in KEV Catalog: No known exploits
- Vulnerable Methods
org/sonatype/nexus/internal/orient/DatabaseServerImpl.createConfiguration()Lcom/orientechnologies/orient/server/config/OServerConfiguration;JVM
org/sonatype/nexus/orient/DatabaseServerImpl.createConfiguration()Lcom/orientechnologies/orient/server/config/OServerConfiguration;JVM
- Source
- National Vulnerability Database