Insertion of Sensitive Information Into Sent Data in Nexus Repository Manager - CVE-2026-77123
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose a webhook shared secret.
The vulnerability exists due to insertion of sensitive information into sent data in the capability read API when handling capability read requests. A remote user can query the API to retrieve a plaintext shared secret configured on a webhook capability.
Exploitation requires the nexus:capabilities:read privilege and a webhook capability configured with a shared secret.