Incorrect authorization in Nexus Repository Manager - CVE-2026-77125
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to modify blobstore configuration without authorization.
The vulnerability exists due to incorrect authorization in blobstore group management REST API endpoints when handling requests to convert an existing blobstore into a group blobstore. A remote user can invoke the endpoints with only the nexus:blobstores:create permission to modify blobstore configuration without authorization.