CVE-2026-5189
Sonatype Nexus 3 vulnerability analysis and mitigation

Overview

CVE-2026-5189 is a hard-coded credentials vulnerability (CWE-798) in Sonatype Nexus Repository Manager affecting all 3.x CE/Pro versions from 3.0.0 through 3.70.5. It allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal OrientDB database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled, or the use of legacy HA-C clustering mode (nexus.clustered=true), which enables the OrientDB binary listener automatically. Disclosed on April 15, 2026, by Sonatype, the vulnerability carries a CVSS v4.0 base score of 9.2 (Critical) (Sonatype Advisory, GitHub Advisory).

Technical details

The root cause is the use of hard-coded credentials (CWE-798) within the OrientDB internal database component of Nexus Repository Manager. When the OrientDB binary listener is enabled — either explicitly via nexus.orient.binaryListenerEnabled=true in nexus.properties, or implicitly through legacy HA-C clustering mode (nexus.clustered=true) — an unauthenticated attacker can connect to the OrientDB binary protocol port using these embedded credentials. This grants full database read/write access and the ability to execute arbitrary OS commands with the privileges of the Nexus process user. The vulnerability was discovered and responsibly disclosed by security researcher Shreyas Chavhan via Sonatype's Bug Bounty Program on HackerOne (Sonatype Advisory, GitHub Advisory).

Impact

Successful exploitation allows a remote, unauthenticated attacker to achieve complete compromise of the Nexus Repository instance, including unauthorized read and write access to the internal database (which may contain repository metadata, credentials, and component data), and execution of arbitrary OS commands as the Nexus process user. This can result in data theft, manipulation or poisoning of repository contents (potentially affecting software supply chains downstream), and full system compromise of the host. Lateral movement within the network is possible if the Nexus process user has access to additional internal resources (Sonatype Advisory, GitHub Advisory).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.042% (13th percentile), indicating a currently low probability of exploitation within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. However, the critical severity and the potential for supply chain impact make it a high-priority target if exploitation details become public.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible Sonatype Nexus Repository Manager instances running versions 3.0.0 through 3.70.5 using tools like Shodan, Censys, or network scanning (e.g., nmap). Look for the OrientDB binary listener port (default: 2424) being open.
  2. Confirm vulnerable configuration: Determine whether the target has nexus.orient.binaryListenerEnabled=true set in nexus.properties, or is running in legacy HA-C mode (nexus.clustered=true), which automatically enables the OrientDB binary listener.
  3. Connect using hard-coded credentials: Use an OrientDB client or custom tooling to connect to the OrientDB binary listener port (typically TCP 2424) using the hard-coded credentials embedded in the Nexus application.
  4. Access internal database: Once authenticated via the hard-coded credentials, perform unauthorized read/write operations on the OrientDB internal database, extracting sensitive repository metadata, user credentials, or component information.
  5. Execute OS commands: Leverage OrientDB's server-side function execution capabilities or other database features to execute arbitrary OS commands on the host system as the Nexus process user, enabling reverse shell establishment, data exfiltration, or further lateral movement (Sonatype Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected inbound TCP connections to OrientDB binary listener port (default: 2424) from external or untrusted IP addresses; unusual outbound connections from the Nexus server process to unknown external hosts.
  • Logs: Nexus Repository access logs showing OrientDB binary protocol connections from unexpected sources; OS-level audit logs recording command execution by the Nexus process user (e.g., nexus or sonatype) for unusual commands such as bash, curl, wget, or python.
  • File System: Unexpected new files, scripts, or web shells created in the Nexus installation directory or temp directories; new cron jobs or scheduled tasks created under the Nexus process user account.
  • Process: Unusual child processes spawned by the Nexus JVM process (e.g., /bin/sh, /bin/bash, curl, wget, python, nc) visible in process trees (Sonatype Advisory).

Mitigation and workarounds

The vulnerability is fixed in Sonatype Nexus Repository Manager version 3.71.0 and later; all users running versions 3.0.0 through 3.70.5 should upgrade immediately (Sonatype Advisory, Release Notes). Note that version 3.71.0 introduces breaking changes, including the removal of OrientDB support and requirements for Java 17 and H2 or PostgreSQL databases — review the upgrade documentation carefully before proceeding. As an immediate workaround for those unable to upgrade, review nexus.properties and remove or set nexus.orient.binaryListenerEnabled=false if present; also ensure legacy HA-C mode (nexus.clustered=true) is not in use. Additionally, restrict network access to the OrientDB binary listener port (default: 2424) using firewall rules to limit exposure to trusted networks only.

Community reactions

Sonatype issued a formal security advisory on April 15, 2026, crediting researcher Shreyas Chavhan for responsible disclosure via their Bug Bounty Program, and emphasized that default configurations are not affected (Sonatype Advisory). Security news outlet SecurityOnline.info covered the vulnerability, highlighting the hard-coded credential risk in Nexus Repository (SecurityOnline). The SANS Internet Storm Center also referenced the vulnerability in a podcast episode shortly after disclosure (SANS ISC). Sonatype later published a blog post emphasizing the risks of running outdated repository software (Sonatype Blog).

Additional resources


SourceThis report was generated using AI

Related Sonatype Nexus 3 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17601HIGH8.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17603HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17600HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17599MEDIUM6.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17598MEDIUM5.3
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management