CVE-2026-11403
HIGHNexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation
Title source: cnaDescription
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user must have an active API key for this vulnerability to be exploitable.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://support.sonatype.com/hc/en-us/articles/52347011450515/
Scores
CVSS v4
8.7
EPSS
0.0035
EPSS Percentile
27.6%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-331
Status
published
Products (1)
Sonatype/Nexus Repository Manager
3.0.0 - 3.93.0
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026