CVE-2026-10741: Nexus Repository Manager - Incorrect Authorization allows credential disclosure via proxy repository configuration
Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configuration that allows a delegated repository administrator to disclose stored upstream proxy credentials.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sonatype Nexus Repository Managerto a version that resolves this vulnerability.Fixed in 3.93.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10741?
CVE-2026-10741 has a risk score of 44, indicating a significant authorization vulnerability.
How does CVE-2026-10741 affect Nexus Repository Manager?
CVE-2026-10741 allows delegated repository administrators to disclose stored upstream proxy credentials through incorrect authorization.
How do I fix CVE-2026-10741?
To mitigate CVE-2026-10741, update your Sonatype Nexus Repository Manager to version 3.93.0 or later.
What versions of Nexus Repository Manager are affected by CVE-2026-10741?
All versions of Sonatype Nexus Repository Manager prior to 3.93.0 are affected by CVE-2026-10741.
What is the underlying issue of CVE-2026-10741?
The underlying issue of CVE-2026-10741 is incorrect authorization in the proxy repository configuration.