Security Advisory

CVE-2026-10748

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-16 17:42:59
Last updated 2026-06-17 03:56:04
Assigner Sonatype
CVSS score 8.6
State PUBLISHED

Description

An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.