216.73.216.6

CVE-2026-3199

· Published 08/04/2026 23:16 · Modified 08/04/2026 23:16

Labels: CVE-2026-3199 103e4ec9-0a87-450b-af77-479448ddef112026-04-08CVE-2026-3199CWE-502

Essential information

Published
08/04/2026 23:16
Modified
08/04/2026 23:16
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
103e4ec9-0a87-450b-af77-479448ddef11
NVD
View on NVD

Affected products (CPE)

ProductCPE
sonatype / nexus repository cpe:2.3:a:sonatype:nexus_repository:3.22.1-3.90.2:*:*:*:*:*:*:*

References