Impact
The flaw in Nexus Repository 3 is a type‑confusion bug in the REST privileges API that allows an authenticated user who can manage privileges to elevate their own rights to full administrator. Classified as CWE-843, it can compromise confidentiality, integrity, and availability by granting unrestricted control over the repository and its configuration.
Affected Systems
Sonatype Nexus Repository 3 versions from 3.19.0 through 3.94.1 are affected. The vulnerability impacts the privilege update endpoint, so any instance running these versions is vulnerable until an updated release is applied.
Risk and Exploitability
The CVSS score of 8.6 marks this as a high‑severity issue. EPSS is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not yet listed in CISA’s KEV catalog. An attacker must possess an authenticated account with privilege‑management permissions, but the type‑confusion flaw can be exploited without additional conditions. Once exploited, the attacker gains full administrator rights, enabling arbitrary configuration changes, data tampering, and potential lateral movement within the environment.
OpenCVE Enrichment