Incorrect authorization in Nexus Repository Manager - CVE-2026-77122
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose member repository metadata.
The vulnerability exists due to incorrect authorization in the repository details REST API endpoint when requesting details directly for a member repository. A remote user can request the endpoint for a member repository to disclose its metadata.
Exploitation requires read or browse permission on a group repository containing the target member repository and knowledge of the member repository name. For proxy repositories, disclosed metadata includes the configured remote URL.