JEXL Expression Sandbox Bypass in Nexus Repository by Sonatype
CVE-2026-17595

5.3MEDIUM

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
7 August 2026

What is CVE-2026-17595?

The Nexus Repository 3 is impacted by a vulnerability that allows accounts with the nexus:selectors:create permission to create JEXL expressions without proper sandboxing. This oversight lets the expressions access internal Java object properties, revealing sensitive JVM class metadata, including class names and class loader information. While this vulnerability does not allow for method invocation or arbitrary code execution, it poses a risk to data confidentiality. The issue has been mitigated in the latest versions by restricting property access to only the intended data types within the JEXL sandbox.

Affected Version(s)

Nexus Repository 3 3.15.0 < 3.95.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Hamza Khaled (hamza0x01)
.