Impact
A vulnerability exists in Sonatype Nexus Repository 3 that allows a user who can modify privilege definitions to alter a wildcard privilege associated with their own role. This change can grant the authenticated user higher permissions—including full administrative rights—without an additional authorization check. The flaw is a missing authorization control that permits privilege escalation to administrator, potentially exposing the repository’s configurations, artifacts, and internal data to the attacker.
Affected Systems
The affected product is Sonatype Nexus Repository 3. Versions from 3.19.0 through 3.94.1 are listed as vulnerable. Administrators should verify that their deployment falls within this version range and plan to update accordingly.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.9, indicating high severity. Although the EPSS score is not available and the issue is not listed in CISA KEV, the risk remains significant. The likely attack vector requires an authenticated user with privilege‑update rights, enabling an attacker to raise their own privileges to full administrator by editing a wildcard privilege. Once escalated, the attacker could manipulate repository configurations, access protected resources, or exfiltrate artifacts.
OpenCVE Enrichment