CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with… (CVE-2026-5189)
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.
AI Analysis
Technical Summary
CVE-2026-5189 is a critical vulnerability in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 caused by the use of hard-coded credentials (CWE-798). An unauthenticated attacker with network access can exploit this issue to gain unauthorized read/write access to the internal database and execute arbitrary OS commands with the privileges of the Nexus process user. Successful exploitation depends on the non-default configuration nexus.orient.binaryListenerEnabled being set to true.
Potential Impact
An attacker can gain unauthorized read and write access to the internal database and execute arbitrary operating system commands as the Nexus process user, potentially leading to full compromise of the Nexus Repository Manager instance. This can result in data theft, data manipulation, or further system compromise. The attack requires network access and the specific configuration setting nexus.orient.binaryListenerEnabled=true to be enabled.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, it is recommended to ensure that the nexus.orient.binaryListenerEnabled configuration is not enabled (i.e., set to false or removed) to prevent exploitation.
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with… (CVE-2026-5189)
Description
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled.
CVSS v3.1
Score 9.8critical
Affected software
pkg:maven/org.sonatype.nexus/nexus-repository-managerRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-5189 is a critical vulnerability in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 caused by the use of hard-coded credentials (CWE-798). An unauthenticated attacker with network access can exploit this issue to gain unauthorized read/write access to the internal database and execute arbitrary OS commands with the privileges of the Nexus process user. Successful exploitation depends on the non-default configuration nexus.orient.binaryListenerEnabled being set to true.
Potential Impact
An attacker can gain unauthorized read and write access to the internal database and execute arbitrary operating system commands as the Nexus process user, potentially leading to full compromise of the Nexus Repository Manager instance. This can result in data theft, data manipulation, or further system compromise. The attack requires network access and the specific configuration setting nexus.orient.binaryListenerEnabled=true to be enabled.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, it is recommended to ensure that the nexus.orient.binaryListenerEnabled configuration is not enabled (i.e., set to false or removed) to prevent exploitation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4gcp-x7jh-x4v7
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-5189"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aade52a55bf5e2cf5edc1d8
Added to database: 09/19/2026, 01:28:10 UTC
Last enriched: 09/19/2026, 01:55:39 UTC
Last updated: 09/19/2026, 02:34:50 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.