---
id: CVE-2026-3199
title: >-
  A vulnerability in the task management component of Sonatype Nexus Repository
  versions 3.22.1 through 3.90.2 allows an authenticated attacker with task
  creation permissions to execute arbitrary code, bypassing the
  nexus.scripts.allowCrea…
summary: >-
  A vulnerability in the task management component of Sonatype Nexus Repository
  versions 3.22.1 through 3.90.2 allows an authenticated attacker with task
  creation permissions to execute arbitrary code, bypassing the
  nexus.scripts.allowCrea…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-502
vendor: sonatype
product: nexus_repository_manager
affected:
  - 'nexus_repository_manager >= 3.22.1, < 3.91.0'
patched:
  - nexus_repository_manager 3.91.0
published: '2026-04-08'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T16:11:14.483'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3199'
references:
  - url: >-
      https://help.sonatype.com/en/sonatype-nexus-repository-3-91-0-release-notes.html
    label: 103e4ec9-0a87-450b-af77-479448ddef11
  - url: 'https://support.sonatype.com/hc/en-us/articles/50615414548499'
    label: 103e4ec9-0a87-450b-af77-479448ddef11
tags:
  - nvd
epss: 0.00556
epssPercentile: 0.45238
ingestedAt: '2026-07-26T10:11:58.843Z'
---

## Overview

A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.

## Affected

- `nexus_repository_manager >= 3.22.1, < 3.91.0`

## Remediation

Upgrade past the affected range:

- `nexus_repository_manager 3.91.0`
