CVE-2026-17601
Sonatype Nexus 3 vulnerability analysis and mitigation

Overview

CVE-2026-17601 is a privilege escalation vulnerability (Missing Authorization, CWE-862) in Sonatype Nexus Repository 3 that allows an authenticated user with permission to update privilege definitions to modify a wildcard privilege already assigned to their own role, granting themselves broader permissions — including full administrative access — without any additional authorization check or role reassignment. It affects Sonatype Nexus Repository 3 versions 3.19.0 through 3.94.x (fixed in 3.95.0), disclosed on August 7, 2026. The vulnerability carries a CVSS v4.0 base score of 8.9 (High), assigned by Sonatype (GitHub Advisory, Sonatype Release Notes).

Technical details

The root cause is CWE-862 (Missing Authorization): when a user with the privilege to update privilege definitions modifies a wildcard privilege already assigned to their own role, the system does not perform an additional authorization check to verify whether the resulting permissions exceed what the user is authorized to hold. This allows the attacker to expand the scope of a wildcard privilege entry (e.g., broadening the resource pattern or action set) without any role reassignment or approval workflow. The attack is network-accessible, requires low privileges (an account with privilege-definition update rights), and has no user interaction requirement, though attack requirements are noted as "Present" (AT:P), indicating some specific deployment or configuration condition must exist (GitHub Advisory, Sonatype Release Notes).

Impact

Successful exploitation allows an authenticated attacker to escalate their own privileges to full administrative access within Nexus Repository 3, resulting in high confidentiality, integrity, and availability impact on both the vulnerable system and subsequent systems. An attacker with admin access could read all repository contents (including sensitive artifacts and credentials), modify or delete repositories and components, alter security configurations, create backdoor accounts, and potentially pivot to downstream systems that trust the repository as a software supply chain source. The CVSS v4.0 scoring reflects total technical impact (GitHub Advisory).

Exploitability

As of the disclosure date (August 7, 2026), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. CISA's SSVC assessment classifies exploitation as "none" and the attack as non-automatable, with total technical impact. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.215% (12th percentile), indicating a low near-term exploitation probability (GitHub Advisory, Sonatype Release Notes).

Exploitation steps

  1. Identify a target account: Obtain or compromise a Nexus Repository 3 account that has been granted the permission to update privilege definitions (e.g., nx-privileges-update or equivalent). This could be a delegated administrator or a developer account with partial admin rights.
  2. Enumerate assigned wildcard privileges: Using the Nexus Repository REST API or UI, enumerate the privileges assigned to the attacker's own role to identify any wildcard-type privilege entries (e.g., privileges with a broad or wildcard resource pattern).
  3. Modify the wildcard privilege definition: Using the Security Management API (e.g., PUT /service/rest/v1/security/privileges/wildcard/{name}), update the wildcard privilege already assigned to the attacker's role to expand its scope — for example, changing the privilege pattern to * (all resources) or adding administrative action types.
  4. Verify privilege escalation: Without any role reassignment or additional approval, the attacker's existing role now carries the expanded privilege. Confirm by accessing administrative endpoints or functions previously restricted.
  5. Achieve full administrative access: With full admin privileges, the attacker can create new admin accounts, exfiltrate repository contents, modify artifacts (supply chain attack), or alter security configurations (GitHub Advisory, Sonatype Release Notes).

Indicators of compromise

  • Logs: Nexus Repository audit logs showing PUT or UPDATE API calls to privilege definition endpoints (e.g., /service/rest/v1/security/privileges/wildcard/) by non-administrative users; sudden appearance of wildcard (*) patterns in privilege definitions not previously present.
  • Logs: Audit log entries showing a low-privileged user account performing administrative actions (user creation, repository deletion, configuration changes) shortly after a privilege definition update.
  • Network: Unexpected API calls to /service/rest/v1/security/privileges/ endpoints from user accounts not typically associated with privilege management.
  • Configuration: Privilege definitions containing overly broad wildcard patterns (e.g., *:*:*) assigned to non-administrative roles; new administrative user accounts created by accounts that should not have that capability.

Mitigation and workarounds

Sonatype has addressed this vulnerability in Nexus Repository 3.95.0, released August 5, 2026. Organizations should upgrade to version 3.95.0 or later as the primary remediation (Sonatype Release Notes). As an interim workaround, restrict the permission to update privilege definitions exclusively to highly trusted administrators, and audit all current privilege definitions and role assignments to identify any unauthorized modifications. Additionally, implement monitoring and alerting on all changes to privilege definitions via the Nexus audit log.

Additional resources


SourceThis report was generated using AI

Related Sonatype Nexus 3 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17601HIGH8.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17603HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17600HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17599MEDIUM6.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17598MEDIUM5.3
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management