CVE-2019-7238

CRITICAL KEV NUCLEI

Sonatype Nexus Repository Manager <3.15.0 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-7238 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added December 10, 2021. EIP tracks 7 public exploits from researchers including mpgn, jas502n, verctor. A Nuclei detection template is also available.

AI-analyzed exploit summary This is a functional exploit for CVE-2019-7238, targeting Nexus Repository Manager 3. It leverages JEXL expression injection to achieve unauthenticated remote code execution via the `previewAssets` endpoint.

Description

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

Exploits (7)

nomisec WORKING POC 153 stars
by mpgn · remote
https://github.com/mpgn/CVE-2019-7238

This is a functional exploit for CVE-2019-7238, targeting Nexus Repository Manager 3. It leverages JEXL expression injection to achieve unauthenticated remote code execution via the `previewAssets` endpoint.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nexus Repository Manager 3 < 3.15.0
No auth needed
Prerequisites: Network access to the target's `/service/extdirect` endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 85 stars
by jas502n · remote
https://github.com/jas502n/CVE-2019-7238

This is a Python-based exploit for CVE-2019-7238, targeting Nexus Repository Manager versions before 3.15.0. It leverages a deserialization vulnerability in the ExtDirect API to achieve remote code execution (RCE) by sending a malicious payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nexus Repository Manager < 3.15.0
No auth needed
Prerequisites: Network access to the target Nexus Repository Manager instance · ExtDirect API endpoint accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 39 stars
by verctor · remote
https://github.com/verctor/nexus_rce_CVE-2019-7238

This repository contains a working exploit for CVE-2019-7238, a remote code execution vulnerability in Nexus Repository Manager. The exploit leverages JEXL expression injection to execute arbitrary commands on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nexus Repository Manager
No auth needed
Prerequisites: Network access to the target Nexus Repository Manager instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 25 stars
by magicming200 · poc
https://github.com/magicming200/CVE-2019-7238_Nexus_RCE_Tool

This repository contains a Java-based tool for detecting and exploiting CVE-2019-7238, a remote code execution vulnerability in Nexus Repository Manager 3 due to insufficient access control. The tool supports both GUI and command-line modes for executing system commands on vulnerable targets.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Nexus Repository Manager 3 (versions before 3.15.0)
No auth needed
Prerequisites: Network access to vulnerable Nexus Repository Manager instance · Java Runtime Environment (JRE) >= 1.6
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WRITEUP 2 stars
by DannyRavi · remote
https://github.com/DannyRavi/nmap-scripts

This repository contains a README describing multiple CVEs, including CVE-2020-0796 (SMBv3 RCE), but does not include actual exploit code or Nmap scripts. It serves as a high-level overview of vulnerabilities without functional PoC.

Classification
Writeup 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Microsoft SMBv3, Sonatype Nexus, Atlassian Crowd, Symantec Messaging Gateway
No auth needed
Prerequisites: none
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by smallpiggy · remote
https://github.com/smallpiggy/CVE-2019-7238

This is a working exploit for CVE-2019-7238, targeting Nexus Repository Manager 3.x. It leverages a JEXL expression injection vulnerability to achieve remote code execution (RCE) by defining a malicious Java class and invoking it.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Nexus Repository Manager 3.x (OSS)
No auth needed
Prerequisites: Network access to the vulnerable Nexus Repository Manager instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Sonatype Nexus Repository Manager <3.15.0 - Remote Code Execution
CRITICALby pikpikcu
FOFA: title="nexus repository manager"

Scores

CVSS v3 9.8
EPSS 0.9438
EPSS Percentile 100.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2021-12-10
VulnCheck KEV 2019-06-12
InTheWild.io 2021-04-08
ENISA EUVD EUVD-2019-16782
Status published
Products (1)
sonatype/nexus_repository_manager 3.0.0 - 3.15.0
Published Mar 21, 2019
KEV Added Dec 10, 2021
Tracked Since Feb 18, 2026