Impact
A user possessing the nexus:settings:update (or equivalent nexus:settings) permission can submit arbitrary realm identifiers through an internal configuration API that does not validate the inputs against registered realms. The unrecognized entries are persisted and re‑evaluated on every realm load via a legacy code path, allowing unintended code to execute within the Nexus Repository process. In certain cases this can also trigger a persistent authentication lockout that remains invisible in the administrative UI. The vulnerability therefore permits arbitrary code execution and potentially denial‑of‑service effects. The attack requires authenticated access with the specific permission, limiting exposure to users with elevated privileges within the system.
Affected Systems
All Sonatype Nexus Repository releases from 2.10 through 3.94.1 are affected, including the legacy Nexus Repository 2 versions (2.10–2.15.2, 2.8.x, 2.9.x) and the Nexus Repository 3 series up to and including 3.94.1.
Risk and Exploitability
The CVSS score of 7.2 places this vulnerability in the high severity range, although the EPSS score is not available and it is not listed in the CISA KEV catalog. Exploitation requires administrative privileges to the internal API, which may reduce the likelihood of widespread exploitation, but the potential impact of arbitrary code execution justifies a moderate to high confidence in risk. Until an official patch is released, the system should be monitored for anomalous realm configuration changes and privileged API usage.
OpenCVE Enrichment