CVE-2026-17599
Sonatype Nexus 3 vulnerability analysis and mitigation

Overview

CVE-2026-17599 is an unverified password change vulnerability in Sonatype Nexus Repository 3 that allows an authenticated user with broad nexus:* permissions to replace the administrator account password outside the intended onboarding flow. The affected versions span from 3.17.0 up to (but not including) 3.95.0. The vulnerability was published on August 7, 2026, with a patch available in version 3.95.0. It carries a CVSS v4.0 base score of 6.9 (Medium) (GitHub Advisory, Sonatype Release Notes).

Technical details

The root cause is classified as CWE-620 (Unverified Password Change): Nexus Repository 3 exposed an endpoint intended solely for changing the administrator password during initial onboarding, but this endpoint failed to verify that the onboarding process was still active. Instead of enforcing a proper state check, the endpoint relied on the presence of a local onboarding artifact, which could be satisfied outside the intended workflow. An attacker holding the nexus:* permission can invoke this endpoint at any time post-onboarding to overwrite the administrator password. Compounding the issue, existing administrator sessions are not invalidated after the password change, meaning the legitimate administrator may remain unaware of the takeover for some time (GitHub Advisory).

Impact

Successful exploitation allows an authenticated user with nexus:* permission to hijack the administrator account by replacing its password, effectively granting themselves full administrative control over the Nexus Repository instance. The primary impact is a high integrity violation — unauthorized modification of administrator credentials — with no direct confidentiality or availability impact scored. However, once administrator access is obtained, an attacker could manipulate hosted artifacts, inject malicious packages into the software supply chain, alter repository configurations, or exfiltrate sensitive component data, significantly amplifying downstream risk (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The vulnerability requires the attacker to already hold the highly privileged nexus:* permission, which limits the attack surface to insider threats or accounts that have been previously compromised. The EPSS score is approximately 0.294% (22nd percentile), indicating a low near-term probability of exploitation. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify a Nexus Repository 3 instance running a version between 3.17.0 and 3.94.x. Confirm the instance is accessible over the network.
  2. Obtain privileged credentials: Acquire credentials for an account holding the nexus:* permission (e.g., through insider access, credential theft, or a previously compromised account).
  3. Locate the onboarding password-change endpoint: Identify the internal API endpoint used during the initial onboarding flow to set the administrator password. This endpoint does not enforce an onboarding-state check.
  4. Invoke the endpoint: Authenticate with the nexus:* account and send a crafted HTTP request to the onboarding password-change endpoint with a new administrator password of the attacker's choosing.
  5. Achieve administrator takeover: The endpoint accepts the request and updates the administrator password without verifying onboarding state. Existing administrator sessions remain active but the legitimate administrator loses the ability to re-authenticate.
  6. Maintain access: Log in as the administrator using the newly set password and perform further actions such as modifying repositories, injecting malicious artifacts, or escalating access to connected systems (GitHub Advisory).

Indicators of compromise

  • Logs: Unexpected calls to the onboarding-related password-change API endpoint in Nexus Repository access logs, particularly outside of initial deployment or setup timeframes; authentication events showing the administrator account logging in from unfamiliar IP addresses or user agents after a password change event.
  • Behavioral: Legitimate administrator accounts suddenly unable to authenticate; administrator password changed without a corresponding support ticket or change management record.
  • Audit Trail: Nexus Repository audit log entries showing a password change action performed by a non-administrator account holding nexus:* permission; configuration changes made under the administrator account shortly after an unexpected password change event.

Mitigation and workarounds

Sonatype has addressed this vulnerability in Nexus Repository 3.95.0, released August 5, 2026. Organizations should upgrade to version 3.95.0 or later as the primary remediation step (Sonatype Release Notes). As an interim measure, administrators should audit all accounts holding the nexus:* permission and restrict this broad privilege grant to only those accounts that strictly require it. Additionally, monitor audit logs for unexpected invocations of onboarding-related endpoints and review administrator account activity for anomalies.

Additional resources


SourceThis report was generated using AI

Related Sonatype Nexus 3 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17601HIGH8.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17603HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17600HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17599MEDIUM6.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17598MEDIUM5.3
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management