NONE · 0

CVE-2026-10748

An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repo...

Vulnerability Description

An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-10748?

CVE-2026-10748 is a documented vulnerability. An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repo...

How severe is CVE-2026-10748?

CVSS scoring is not yet available for CVE-2026-10748. Check NVD for updates.

Is there a patch for CVE-2026-10748?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.