Unauthorized Access via API Key Generation in Sonatype Nexus Repo Manager
CVE-2026-11403 Published on July 14, 2026
Nexus Repository Manager - Insufficient Entropy in Format-Specific API Key Generation
A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may allow a remote attacker to gain unauthorized access to repository operations as a targeted user. A format-specific API key realm (NuGet API Key, Docker Bearer Token, or npm Bearer Token) must be enabled and the targeted user must have an active API key for this vulnerability to be exploitable.
Weakness Type
Insufficient Entropy
The software uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
Products Associated with CVE-2026-11403
Want to know whenever a new CVE is published for Sonatype Nexus Repository Manager? stack.watch will email you.
Affected Versions
Sonatype Nexus Repository Manager:- Version 3.0.0 and below 3.93.0 is affected.