JEXL Expression Sandbox Bypass in Nexus Repository by Sonatype
CVE-2026-17595
5.3MEDIUM
What is CVE-2026-17595?
The Nexus Repository 3 is impacted by a vulnerability that allows accounts with the nexus:selectors:create permission to create JEXL expressions without proper sandboxing. This oversight lets the expressions access internal Java object properties, revealing sensitive JVM class metadata, including class names and class loader information. While this vulnerability does not allow for method invocation or arbitrary code execution, it poses a risk to data confidentiality. The issue has been mitigated in the latest versions by restricting property access to only the intended data types within the JEXL sandbox.
Affected Version(s)
Nexus Repository 3 3.15.0 < 3.95.0
