CVE-2019-7238: Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-12-10. EPSS: 77.1% chance of exploitation in the next 30 days.

Sonatype Nexus Repository Manager before 3.15.0 has Incorrect Access Control.

Affected products

  • Sonatype Nexus Repository Manager: from 3.0.0, before 3.15.0 (fixed in 3.15.0)

Published 2019-03-21. Last modified 2026-06-17.