MEDIUMVulnerability

CVE-2026-77123

Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account holding the nexus:capabilities:read privilege can retrieve the plaintext shared secret configured on a webhook capability, which is intended to be masked from all API responses. This issue affects Nexus Repository 3 versions 3.2.0 through 3.95.x, and is fixed in version 3.96.0.

Properties

severity
MEDIUM
score
6.5
cve_id
CVE-2026-77123
signal_observed_at
2026-09-23T04:35:08+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
published_at
2026-09-02T18:21:24.477
last_modified
2026-09-22T17:24:39.730

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Insertion of Sensitive Information Into Sent Data

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-77123 — Ninja Signal Threat Intelligence | Ninja Signal