CVE-2026-3199 | Security Details | Sonatype Guide
CVE-2026-3199
A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.
Published Mar 31, 2026
CVSS Score
Critical 9.4
Security Details
Components Impacted
- Sonatype Research
CVE-2026-3199 Security Details
CVE ID: CVE-2026-3199
CWE: CWE-502 Learn more about CWE-502
CVE Description: A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.
Published: Mar 31, 2026
CVSS Score & Severity
Score: 9.4 (Critical)
CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L
EPSS Score
0.088%
Malware
malware
KEV Status
Not in KEV Catalog: No known exploits
Vulnerable Methods
org/sonatype/nexus/coreui/TaskComponent.create(Lorg/sonatype/nexus/coreui/TaskXO;)Lorg/sonatype/nexus/coreui/TaskXO;org/sonatype/nexus/coreui/TaskComponent.update(Lorg/sonatype/nexus/coreui/TaskXO;)Lorg/sonatype/nexus/coreui/TaskXO;
JVM
Vulnerable params: 0
Affected Ecosystems
- Source: National Vulnerability Database