Executive Summary


This writeup documents the complete exploitation chain for the Nexus target system, from initial reconnaissance through root compromise. The attack leveraged:



Exposed credentials in Git commit history

Authenticated RCE via CRM file upload vulnerability (CVE-2026-38526)

Path traversal in privileged template synchronization...