CVE-2026-17598
Sonatype Nexus 3 vulnerability analysis and mitigation

Overview

CVE-2026-17598 is a task configuration tampering vulnerability in Sonatype Nexus Repository 3 that allows authenticated users with limited task creation permissions to overwrite the configuration of unrelated, existing scheduled tasks. The flaw was disclosed on August 7, 2026, and affects versions 3.91.0 through 3.94.x (specifically versions from 3.91.0 up to but not including 3.95.0). It carries a CVSS v4.0 base score of 5.3 (Medium), assigned by Sonatype (Github Advisory, Sonatype Release Notes).

Technical details

The root cause is classified as CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes): the application fails to filter internal configuration keys from user-supplied task properties when creating or updating scheduled tasks via the administrative UI. An attacker can craft a property value that includes internal configuration keys, causing the system to overwrite the configuration of an existing, unrelated task rather than creating a new one. Exploitation requires only low-level privileges (permission to create at least one scheduled task type) and no user interaction, making it accessible to any account with partial administrative access (Github Advisory, Sonatype Release Notes).

Impact

Successful exploitation allows an authenticated attacker to tamper with the configuration of arbitrary scheduled tasks, potentially disrupting automated operations, altering task schedules, or modifying task parameters in ways that could affect system integrity and availability. The CVSS v4.0 assessment indicates low integrity and low availability impact on the vulnerable system, with no confidentiality impact and no impact on subsequent systems. While the vulnerability does not enable direct code execution or data exfiltration, it could be leveraged to disrupt repository operations or manipulate task behavior in ways that indirectly affect the software supply chain pipeline (Github Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. CISA's SSVC assessment classifies exploitation as "none" and the technical impact as "partial," with the attack not being automatable. The EPSS score is approximately 0.253% (17th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Sonatype Release Notes).

Exploitation steps

  1. Reconnaissance: Identify a Sonatype Nexus Repository 3 instance running versions 3.91.0 through 3.94.x. Confirm access to the administrative UI with an account that holds permission to create at least one scheduled task type.
  2. Enumerate existing tasks: Navigate to the administrative UI's task management section to identify existing scheduled tasks whose configurations could be targeted for overwrite.
  3. Craft malicious task property: When creating or updating a scheduled task, supply a crafted property value that includes internal configuration keys normally reserved for system use (e.g., keys that reference the ID or configuration namespace of an existing, unrelated task).
  4. Submit the request: Submit the task creation or update form. Due to insufficient filtering, the system processes the internal configuration key from the user-supplied input and overwrites the configuration of the targeted existing task instead of creating a new one.
  5. Achieve objective: The targeted task's configuration is now overwritten, potentially disrupting its scheduled operation, altering its parameters, or causing it to malfunction — impacting repository availability or integrity (Github Advisory).

Indicators of compromise

  • Logs: Audit log entries showing unexpected task configuration changes, particularly where a task creation event results in modification of a pre-existing, unrelated task; look for task update events attributed to accounts that do not normally manage those specific tasks.
  • Application Behavior: Scheduled tasks exhibiting unexpected configuration changes (altered schedules, parameters, or types) without corresponding legitimate administrative actions.
  • Access Patterns: Low-privileged accounts with task creation permissions accessing or modifying task configurations outside their normal scope in the administrative UI.

Mitigation and workarounds

Sonatype has addressed this vulnerability in Nexus Repository 3.95.0, released August 5, 2026. Organizations should upgrade to version 3.95.0 or later as the primary remediation. As interim workarounds, restrict administrative UI access and scheduled task creation permissions to only trusted personnel, and monitor audit logs for unexpected task configuration modifications. Additional input validation at the application level can also reduce exposure until an upgrade is possible (Sonatype Release Notes).

Additional resources


SourceThis report was generated using AI

Related Sonatype Nexus 3 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17601HIGH8.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17603HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17600HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17599MEDIUM6.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17598MEDIUM5.3
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management