
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-17598 is a task configuration tampering vulnerability in Sonatype Nexus Repository 3 that allows authenticated users with limited task creation permissions to overwrite the configuration of unrelated, existing scheduled tasks. The flaw was disclosed on August 7, 2026, and affects versions 3.91.0 through 3.94.x (specifically versions from 3.91.0 up to but not including 3.95.0). It carries a CVSS v4.0 base score of 5.3 (Medium), assigned by Sonatype (Github Advisory, Sonatype Release Notes).
The root cause is classified as CWE-915 (Improperly Controlled Modification of Dynamically-Determined Object Attributes): the application fails to filter internal configuration keys from user-supplied task properties when creating or updating scheduled tasks via the administrative UI. An attacker can craft a property value that includes internal configuration keys, causing the system to overwrite the configuration of an existing, unrelated task rather than creating a new one. Exploitation requires only low-level privileges (permission to create at least one scheduled task type) and no user interaction, making it accessible to any account with partial administrative access (Github Advisory, Sonatype Release Notes).
Successful exploitation allows an authenticated attacker to tamper with the configuration of arbitrary scheduled tasks, potentially disrupting automated operations, altering task schedules, or modifying task parameters in ways that could affect system integrity and availability. The CVSS v4.0 assessment indicates low integrity and low availability impact on the vulnerable system, with no confidentiality impact and no impact on subsequent systems. While the vulnerability does not enable direct code execution or data exfiltration, it could be leveraged to disrupt repository operations or manipulate task behavior in ways that indirectly affect the software supply chain pipeline (Github Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. CISA's SSVC assessment classifies exploitation as "none" and the technical impact as "partial," with the attack not being automatable. The EPSS score is approximately 0.253% (17th percentile), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory, Sonatype Release Notes).
Sonatype has addressed this vulnerability in Nexus Repository 3.95.0, released August 5, 2026. Organizations should upgrade to version 3.95.0 or later as the primary remediation. As interim workarounds, restrict administrative UI access and scheduled task creation permissions to only trusted personnel, and monitor audit logs for unexpected task configuration modifications. Additional input validation at the application level can also reduce exposure until an upgrade is possible (Sonatype Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."