CVE-2026-3438 | Security Details | Sonatype Guide

CVE-2026-3438

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

Published Mar 27, 2026

CVSS Score
Medium
5.1

Security Details

Components Impacted

CVE Details

CVSS Score & Severity

Malware

Affected Ecosystems

References