
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5189 is a hard-coded credentials vulnerability (CWE-798) in Sonatype Nexus Repository Manager affecting all 3.x CE/Pro versions from 3.0.0 through 3.70.5. It allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal OrientDB database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.orient.binaryListenerEnabled=true configuration to be enabled, or the use of legacy HA-C clustering mode (nexus.clustered=true), which enables the OrientDB binary listener automatically. Disclosed on April 15, 2026, by Sonatype, the vulnerability carries a CVSS v4.0 base score of 9.2 (Critical) (Sonatype Advisory, GitHub Advisory).
The root cause is the use of hard-coded credentials (CWE-798) within the OrientDB internal database component of Nexus Repository Manager. When the OrientDB binary listener is enabled — either explicitly via nexus.orient.binaryListenerEnabled=true in nexus.properties, or implicitly through legacy HA-C clustering mode (nexus.clustered=true) — an unauthenticated attacker can connect to the OrientDB binary protocol port using these embedded credentials. This grants full database read/write access and the ability to execute arbitrary OS commands with the privileges of the Nexus process user. The vulnerability was discovered and responsibly disclosed by security researcher Shreyas Chavhan via Sonatype's Bug Bounty Program on HackerOne (Sonatype Advisory, GitHub Advisory).
Successful exploitation allows a remote, unauthenticated attacker to achieve complete compromise of the Nexus Repository instance, including unauthorized read and write access to the internal database (which may contain repository metadata, credentials, and component data), and execution of arbitrary OS commands as the Nexus process user. This can result in data theft, manipulation or poisoning of repository contents (potentially affecting software supply chains downstream), and full system compromise of the host. Lateral movement within the network is possible if the Nexus process user has access to additional internal resources (Sonatype Advisory, GitHub Advisory).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.042% (13th percentile), indicating a currently low probability of exploitation within 30 days (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. However, the critical severity and the potential for supply chain impact make it a high-priority target if exploitation details become public.
nexus.orient.binaryListenerEnabled=true set in nexus.properties, or is running in legacy HA-C mode (nexus.clustered=true), which automatically enables the OrientDB binary listener.nexus or sonatype) for unusual commands such as bash, curl, wget, or python./bin/sh, /bin/bash, curl, wget, python, nc) visible in process trees (Sonatype Advisory).The vulnerability is fixed in Sonatype Nexus Repository Manager version 3.71.0 and later; all users running versions 3.0.0 through 3.70.5 should upgrade immediately (Sonatype Advisory, Release Notes). Note that version 3.71.0 introduces breaking changes, including the removal of OrientDB support and requirements for Java 17 and H2 or PostgreSQL databases — review the upgrade documentation carefully before proceeding. As an immediate workaround for those unable to upgrade, review nexus.properties and remove or set nexus.orient.binaryListenerEnabled=false if present; also ensure legacy HA-C mode (nexus.clustered=true) is not in use. Additionally, restrict network access to the OrientDB binary listener port (default: 2424) using firewall rules to limit exposure to trusted networks only.
Sonatype issued a formal security advisory on April 15, 2026, crediting researcher Shreyas Chavhan for responsible disclosure via their Bug Bounty Program, and emphasized that default configurations are not affected (Sonatype Advisory). Security news outlet SecurityOnline.info covered the vulnerability, highlighting the hard-coded credential risk in Nexus Repository (SecurityOnline). The SANS Internet Storm Center also referenced the vulnerability in a podcast episode shortly after disclosure (SANS ISC). Sonatype later published a blog post emphasizing the risks of running outdated repository software (Sonatype Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."