THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-11403 (HIGH 7.5) — A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token)

[NVD] CVE-2026-11403 (HIGH 7.5) — A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token)

lownvdPublished 2026-07-14

CVE-2026-11403 CVSS: 7.5 HIGH Published: 2026-07-14T16:16:44.217

A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user must have an ac

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-11403