
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-17601 is a privilege escalation vulnerability (Missing Authorization, CWE-862) in Sonatype Nexus Repository 3 that allows an authenticated user with permission to update privilege definitions to modify a wildcard privilege already assigned to their own role, granting themselves broader permissions — including full administrative access — without any additional authorization check or role reassignment. It affects Sonatype Nexus Repository 3 versions 3.19.0 through 3.94.x (fixed in 3.95.0), disclosed on August 7, 2026. The vulnerability carries a CVSS v4.0 base score of 8.9 (High), assigned by Sonatype (GitHub Advisory, Sonatype Release Notes).
The root cause is CWE-862 (Missing Authorization): when a user with the privilege to update privilege definitions modifies a wildcard privilege already assigned to their own role, the system does not perform an additional authorization check to verify whether the resulting permissions exceed what the user is authorized to hold. This allows the attacker to expand the scope of a wildcard privilege entry (e.g., broadening the resource pattern or action set) without any role reassignment or approval workflow. The attack is network-accessible, requires low privileges (an account with privilege-definition update rights), and has no user interaction requirement, though attack requirements are noted as "Present" (AT:P), indicating some specific deployment or configuration condition must exist (GitHub Advisory, Sonatype Release Notes).
Successful exploitation allows an authenticated attacker to escalate their own privileges to full administrative access within Nexus Repository 3, resulting in high confidentiality, integrity, and availability impact on both the vulnerable system and subsequent systems. An attacker with admin access could read all repository contents (including sensitive artifacts and credentials), modify or delete repositories and components, alter security configurations, create backdoor accounts, and potentially pivot to downstream systems that trust the repository as a software supply chain source. The CVSS v4.0 scoring reflects total technical impact (GitHub Advisory).
As of the disclosure date (August 7, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. CISA's SSVC assessment classifies exploitation as "none" and the attack as non-automatable, with total technical impact. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.215% (12th percentile), indicating a low near-term exploitation probability (GitHub Advisory, Sonatype Release Notes).
nx-privileges-update or equivalent). This could be a delegated administrator or a developer account with partial admin rights.PUT /service/rest/v1/security/privileges/wildcard/{name}), update the wildcard privilege already assigned to the attacker's role to expand its scope — for example, changing the privilege pattern to * (all resources) or adding administrative action types.PUT or UPDATE API calls to privilege definition endpoints (e.g., /service/rest/v1/security/privileges/wildcard/) by non-administrative users; sudden appearance of wildcard (*) patterns in privilege definitions not previously present./service/rest/v1/security/privileges/ endpoints from user accounts not typically associated with privilege management.*:*:*) assigned to non-administrative roles; new administrative user accounts created by accounts that should not have that capability.Sonatype has addressed this vulnerability in Nexus Repository 3.95.0, released August 5, 2026. Organizations should upgrade to version 3.95.0 or later as the primary remediation (Sonatype Release Notes). As an interim workaround, restrict the permission to update privilege definitions exclusively to highly trusted administrators, and audit all current privilege definitions and role assignments to identify any unauthorized modifications. Additionally, implement monitoring and alerting on all changes to privilege definitions via the Nexus audit log.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."