CVE-2026-10748
Received Received - Intake
Authenticated Command Injection in Sonatype Nexus Repository

Publication date: 2026-06-16

Last updated on: 2026-06-16

Assigner: Sonatype

Description
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-16
Last Modified
2026-06-16
Generated
2026-06-16
AI Q&A
2026-06-16
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
sonatype nexus_repository to 3.92.0 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-10748 is a Remote Code Execution (RCE) vulnerability in Sonatype Nexus Repository Manager 3 versions before 3.92.0.

An authenticated user who has the nx-licensing-create privilege can upload a specially crafted license file.

This malicious license file can cause the server to execute arbitrary operating system commands with the privileges of the Nexus process user.

Impact Analysis

Successful exploitation of this vulnerability could lead to full server compromise.

An attacker with the nx-licensing-create privilege can execute arbitrary commands on the server, potentially gaining control over the system.

This can result in unauthorized access, data theft, service disruption, or further attacks within the network.

Mitigation Strategies

To mitigate the CVE-2026-10748 vulnerability, you should immediately upgrade Sonatype Nexus Repository Manager to version 3.92.0 or later, where the issue has been fixed.

Additionally, review and restrict the nx-licensing-create privilege to trusted administrators only to reduce the risk of exploitation.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10748. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart