THREAT OPS › Threat News › [NVD] CVE-2026-11403 (HIGH 7.5) — A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token)
[NVD] CVE-2026-11403 (HIGH 7.5) — A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token)
CVE-2026-11403 CVSS: 7.5 HIGH Published: 2026-07-14T16:16:44.217
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user must have an ac
Indicators of compromise
- CVE-2026-11403cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-11403