Status: UPDATED
| Advisory ID: CVE-2026-17599
Key Details
| CVE | CVE-2026-17599 |
| CVSS Score / Version | 7.2 (High) / CVSS v3.1 |
| Updated | 2026-09-22 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is high; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | sonatype nexus_repository_manager |
| Classified as | CWE-620 (Unverified Password Change) |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change. (NVD)
What to Do
Monitor sonatype's web page for any future patch releases. See vendor advisory link below.
References