CVE-2026-10748: Nexus Repository 3 - Remote Code Execution via License Deserialization
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
sonatype/nexus-repositoryto a version that resolves this vulnerability.Fixed in 3.92.0 - Configuration
Revoke the nx-licensing-create privilege from any users who do not require it; restrict assignment of this privilege to trusted administrators and audit current privilege assignments.
Sonatype Nexus Repository 3 (security/privileges) nx-licensing-create = revoke or restrict to trusted administrators
Event History
Frequently Asked Questions
What is the severity of CVE-2026-10748?
CVE-2026-10748 has a high severity rating of 8.6.
How do I fix CVE-2026-10748?
To fix CVE-2026-10748, upgrade to Sonatype Nexus Repository 3 version 3.92.0 or later.
What is the risk associated with CVE-2026-10748?
CVE-2026-10748 has a risk score of 72, indicating a significant potential threat.
Who is affected by CVE-2026-10748?
CVE-2026-10748 affects authenticated users with the nx-licensing-create privilege in Sonatype Nexus Repository 3.
What type of vulnerability is CVE-2026-10748?
CVE-2026-10748 is a remote code execution vulnerability that allows arbitrary command execution through license deserialization.