SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77123

MEDIUM · CVSS 6 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Nexus Repository 3 is vulnerable to a sensitive information disclosure issue within its capability read API, allowing accounts with the nexus:capabilities:read privilege to access plaintext shared secrets intended to be masked. This vulnerability impacts versions 3.2.0 through 3.95.x and could lead to unauthorized access to sensitive configuration data. Organizations using affected versions should prioritize upgrading to version 3.96.0 to mitigate potential security risks.

CVE
CVE-2026-77123
Severity
MEDIUM
CVSS
6
EPSS
0.27%

Original NVD Description

Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all API responses. This issue affects Nexus Repository 3 versions 3.2.0 through 3.95.x, and is fixed in version 3.96.0.