Authorization Flaw in Sonatype Nexus Repository Affects Multiple Versions
CVE-2026-17594

8.2HIGH

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
7 August 2026

What is CVE-2026-17594?

An incorrect authorization vulnerability has been identified in the Nexus Repository 3 CE/Pro, specifically affecting versions 3.0.0 through 3.94.x. This flaw allows a user with delegated repository-admin privileges to create repositories of unauthorized formats. The validation process in the repository-creation user interface mistakenly checks authorization against one field while using another, controllable field to determine the actual repository format. This issue is not present for anonymous users who, by default, cannot hold these privileges. The vulnerability has been addressed in version 3.95.0.

Affected Version(s)

Nexus Repository 3 3.0.0 < 3.95.0

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mayur Udiniya aka roughwire (https://x.com/roughwire/)
.