CVE-2026-5189: Nexus Repository 3 - Hardcoded Credential in Internal Database Component
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5189?
CVE-2026-5189 is considered a critical vulnerability due to the potential for unauthorized access to the internal database.
How do I fix CVE-2026-5189?
To fix CVE-2026-5189, update Sonatype Nexus Repository Manager to version 3.71.0 or later, which removes the hardcoded credentials.
What versions of Sonatype Nexus Repository Manager are affected by CVE-2026-5189?
Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 are affected by CVE-2026-5189.
What impact does CVE-2026-5189 have on my system?
CVE-2026-5189 allows unauthenticated attackers with network access to potentially gain unauthorized read/write access to your internal database.
Is there a workaround for CVE-2026-5189 if I cannot immediately update?
There are no official workarounds for CVE-2026-5189, so immediate updating is recommended to mitigate risk.