CVE-2026-3199 Details
Description
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.
A remote code execution vulnerability has been identified in the task management component of Sonatype Nexus Repository versions 3.22.1 prior to 3.90.2. This vulnerability allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control. Successful exploitation leads to a full compromise of the Nexus server and its contents.
Users are advised to upgrade to Sonatype Nexus Repository version 3.91.0 or later. The latest version can be downloaded from the Sonatype Nexus Repository Downloads page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.sonatype.com/en/sonatype-nexus-repository-3-91-0-release-notes.html | Sonatype | Release Notes |
| https://support.sonatype.com/hc/en-us/articles/50615414548499 | Sonatype | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-502 | Deserialization of Untrusted Data | Sonatype |
Affected Products
| Product | Versions |
|---|---|
| sonatype nexus repository manager | >= 3.22.1, < 3.91.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | Initial Analysis | [email protected] |
| Jul 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | Sonatype |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 8, 2026 | New CVE Received | Sonatype |