CVE-2026-11403: Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user must have an active API key for this vulnerability to be exploitable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11403?
The severity of CVE-2026-11403 is high, rated at 8.7 on the CVSS scale.
How do I fix CVE-2026-11403?
To fix CVE-2026-11403, update Sonatype Nexus Repository Manager to the latest version that addresses the vulnerability.
What are the effects of CVE-2026-11403?
CVE-2026-11403 may allow a remote attacker to gain unauthorized access to repository operations as a targeted user.
Which versions of Sonatype Nexus Repository Manager are affected by CVE-2026-11403?
CVE-2026-11403 affects specific versions of Sonatype Nexus Repository Manager that utilize format-specific API key generation.
Can CVE-2026-11403 be exploited remotely?
Yes, CVE-2026-11403 can be exploited remotely by an attacker if the format-specific API key realm is enabled.