CVE-2026-5189 is a hard-coded credentials vulnerability affecting Sonatype Nexus Repository Manager versions 3.0.0 through 3.70.5. An unauthenticated attacker with network access can exploit this flaw to gain unauthorized read/write access to the internal database and execute arbitrary operating system commands with the privileges of the Nexus process user, provided the non-default configuration option nexus.orient.binaryListenerEnabled is set to true. The vulnerability carries a FAUCET Risk Score of 43.0/100 and has an extremely low EPSS score of 0.000220000, indicating minimal prevalence across similar vulnerabilities. Exploitation is not currently documented in known exploited vulnerabilities lists, and community attention appears limited based on available indicators. Organizations running affected Nexus versions should verify their configuration settings and apply updates to versions 3.70.6 or later, particularly if the binary listener option has been intentionally enabled.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sonatype | Nexus Repository | >= 3.0.0, < 3.71.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.