Vulnerability in Nexus Repository 3 and 2 by Sonatype: Unvalidated Realm Identifier Submission
CVE-2026-17593
7.2HIGH
What is CVE-2026-17593?
A security issue in Nexus Repository 3 and the legacy Nexus Repository 2 allows users with nexus:settings:update permissions to exploit an unvalidated submission of realm identifiers via an internal configuration API. This weakness persists unrecognized entries and re-evaluates them on each realm load through a legacy code path. Consequently, this may lead to the execution of unintended code within the Nexus Repository process and could also trigger persistent authentication lockouts that remain undetectable through the administrative interface.
Affected Version(s)
Nexus Repository 2.8.0 < 3.95.0
References
CVSS V4
Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mayur Udiniya aka roughwire (https://x.com/roughwire/)
