NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-3438
Summary

A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interaction.

Publication Date April 9, 2026, 8:16 a.m.
Registration Date April 15, 2026, 11:33 a.m.
Last Update April 14, 2026, 12:02 a.m.
Related information, measures and tools
Common Vulnerabilities List