# CVE-2026-3438

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

Published Mar 27, 2026

**CVSS Score**  
Medium  
5.1

## Security Details

### Components Impacted

- Sonatype Research

### CVE Details

- **CVE ID**: CVE-2026-3438
- **CWE**: CWE-79 [Learn more about CWE-79](https://cwe.mitre.org/data/definitions/79.html)
- **CVE Description**: A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.
- **Published**: Mar 27, 2026

### CVSS Score & Severity

- **Score**: 5.1 Medium
- **CVSS Vector**: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
- **EPSS Score**: 0.359%

### Malware

- **KEV Status**: Not in KEV Catalog: No known exploits

### Affected Ecosystems

- **Source**: National Vulnerability Database

### References

- [Sonatype Support](https://support.sonatype.com/hc/en-us/articles/50609137161363)
