THREAT OPS › Threat News › [NVD] CVE-2026-5189 (CRITICAL 9.8) — CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process
[NVD] CVE-2026-5189 (CRITICAL 9.8) — CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process
CVE-2026-5189 CVSS: 9.8 CRITICAL Published: 2026-04-15T19:16:37.990
CWE-798: Use of Hard-coded Credentials in Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5 allows an unauthenticated attacker with network access to gain unauthorized read/write access to the internal database and execute arbitrary OS commands as the Nexus process user. Exploitation requires the non-default nexus.o
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-5189cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-5189