CVE-2026-3199 | Security Details | Sonatype Guide

CVE-2026-3199

A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.

Published Mar 31, 2026

CVSS Score

Critical 9.4

Security Details

Components Impacted

CVE-2026-3199 Security Details

CVE ID: CVE-2026-3199
CWE: CWE-502 Learn more about CWE-502

CVE Description: A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.

Published: Mar 31, 2026

CVSS Score & Severity

Score: 9.4 (Critical)
CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L

EPSS Score

0.088%

Malware

malware

KEV Status

Not in KEV Catalog: No known exploits

Vulnerable Methods

JVM

Vulnerable params: 0

Affected Ecosystems

References