CVE-2026-10748
Severity CVSS v4.0:
HIGH
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
16/06/2026
Last modified:
16/06/2026
Description
An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH



