CVE-2026-5189 Details
Description
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.
A vulnerability exists in Sonatype Nexus Repository Manager versions 3.0.0 prior to 3.70.5, due to hard-coded credentials in an internal database component. This flaw allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary operating system commands as the Nexus process user. Exploitation of this vulnerability requires the non-default 'nexus.orient.binaryListenerEnabled=true' configuration to be enabled.
Users are advised to upgrade to Sonatype Nexus Repository version 3.71.0 or later. Additionally, review the 'nexus.properties' configuration file for the 'nexus.orient.binaryListenerEnabled=true' setting. If this setting is present and not required, it should be removed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.sonatype.com/en/sonatype-nexus-repository-3-71-0-release-notes.html | Sonatype | Release Notes |
| https://support.sonatype.com/hc/en-us/articles/50817138825491 | Sonatype | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-798 | Use of Hard-coded Credentials | Sonatype |
Affected Products
| Product | Versions |
|---|---|
| sonatype nexus repository manager | >= 3.0.0, < 3.71.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 18, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | Sonatype |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 15, 2026 | New CVE Received | Sonatype |