By vendor

Sonatype vulnerabilities

Known CVEs affecting Sonatype products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2026-10741MEDIUM 4.9

    Sonatype Nexus Repository Manager versions before 3.93.0 have a flaw that allows repository administrators with delegated authority to access upstream proxy credentials that should be protected. When a Nexus instance is configured to proxy external repositories, it stores credentials needed to authenticate with those upstream servers. An administrator with limited permissions—one who manages only specific repositories—can exploit this vulnerability to retrieve credentials that should remain hidden even from them. This is a credential disclosure issue with medium severity that requires administrator-level access to exploit.