VYPR
High severityNVD Advisory· Published Jun 16, 2026· Updated Jun 16, 2026

CVE-2026-10748

CVE-2026-10748

Description

Authenticated users with nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary OS commands as the Nexus process user in Sonatype Nexus Repository before 3.92.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated users with nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary OS commands as the Nexus process user in Sonatype Nexus Repository before 3.92.0.

Vulnerability

A command injection vulnerability exists in the license file upload functionality of Sonatype Nexus Repository. An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file that, when processed, executes arbitrary operating system commands as the Nexus process user. This affects Sonatype Nexus Repository versions prior to 3.92.0 [1].

Exploitation

An attacker must have a valid account with the nx-licensing-create privilege. The attacker crafts a malicious license file and uploads it via the licensing interface. The file is then processed by the Nexus application, leading to the execution of arbitrary commands. No additional user interaction is required beyond the upload step.

Impact

Successful exploitation allows an attacker to execute arbitrary operating system commands with the privileges of the Nexus process user. This can result in full compromise of the Nexus Repository instance, including unauthorized access to stored artifacts, credentials, and the ability to disrupt service or pivot to other systems.

Mitigation

The vulnerability is fixed in Sonatype Nexus Repository version 3.92.0 and later [1]. Users should upgrade to at least version 3.92.0 immediately. If an upgrade is not feasible, restrict the nx-licensing-create privilege to only trusted users and monitor for any suspicious license upload activity.

AI Insight generated on Jun 16, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.