
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-17599 is an unverified password change vulnerability in Sonatype Nexus Repository 3 that allows an authenticated user with broad nexus:* permissions to replace the administrator account password outside the intended onboarding flow. The affected versions span from 3.17.0 up to (but not including) 3.95.0. The vulnerability was published on August 7, 2026, with a patch available in version 3.95.0. It carries a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Sonatype Release Notes).
The root cause is classified as CWE-620 (Unverified Password Change): Nexus Repository 3 exposed an endpoint intended solely for changing the administrator password during initial onboarding, but this endpoint failed to verify that the onboarding process was still active. Instead of enforcing a proper state check, the endpoint relied on the presence of a local onboarding artifact, which could be satisfied outside the intended workflow. An attacker holding the nexus:* permission can invoke this endpoint at any time post-onboarding to overwrite the administrator password. Compounding the issue, existing administrator sessions are not invalidated after the password change, meaning the legitimate administrator may remain unaware of the takeover for some time (GitHub Advisory).
Successful exploitation allows an authenticated user with nexus:* permission to hijack the administrator account by replacing its password, effectively granting themselves full administrative control over the Nexus Repository instance. The primary impact is a high integrity violation — unauthorized modification of administrator credentials — with no direct confidentiality or availability impact scored. However, once administrator access is obtained, an attacker could manipulate hosted artifacts, inject malicious packages into the software supply chain, alter repository configurations, or exfiltrate sensitive component data, significantly amplifying downstream risk (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The vulnerability requires the attacker to already hold the highly privileged nexus:* permission, which limits the attack surface to insider threats or accounts that have been previously compromised. The EPSS score is approximately 0.294% (22nd percentile), indicating a low near-term probability of exploitation. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
nexus:* permission (e.g., through insider access, credential theft, or a previously compromised account).nexus:* account and send a crafted HTTP request to the onboarding password-change endpoint with a new administrator password of the attacker's choosing.nexus:* permission; configuration changes made under the administrator account shortly after an unexpected password change event.Sonatype has addressed this vulnerability in Nexus Repository 3.95.0, released August 5, 2026. Organizations should upgrade to version 3.95.0 or later as the primary remediation step (Sonatype Release Notes). As an interim measure, administrators should audit all accounts holding the nexus:* permission and restrict this broad privilege grant to only those accounts that strictly require it. Additionally, monitor audit logs for unexpected invocations of onboarding-related endpoints and review administrator account activity for anomalies.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."