CVE-2021-29158Medium· 4.9▾ SunlitSonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
Sonatype Nexus Repository Manager 3 Pro up to and including 3.30.0 has Incorrect Access Control.
nexus_repository_manager <= 3.30.0Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2020-11753High· 8.8An issue was discovered in Sonatype Nexus Repository Manager in versions 3.21.1 and 3.22.0
CVE-2026-17594Medium· 4.9Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface
CVE-2026-77122Medium· 4.3An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) in Sonatype Nexus Repository 3 allowed an account holding read or browse permission on a group repository to retrieve …
CVE-2026-77125High· 7.1A vulnerability was identified in Sonatype Nexus Repository 3 in which two blobstore group management REST API endpoints did not correctly enforce the intended authorization check
CVE-2026-17601High· 7.2A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, withou…
CVE-2021-40143High· 8.2Sonatype Nexus Repository 3.x through 3.33.1-01 is vulnerable to an HTTP header injection