Password Change Vulnerability in Nexus Repository by Sonatype
CVE-2026-17599
6.9MEDIUM
What is CVE-2026-17599?
Nexus Repository 3 has a security weakness in its password change feature, which can be exploited during the onboarding phase. Specifically, an endpoint intended for changing the administrator password does not adequately verify if onboarding is active, allowing unauthorized account holders with nexus:* permissions to change the administrator's password outside the intended context. This security lapse means that existing user sessions remain active even after a password change, increasing the risk of unauthorized access and control.
Affected Version(s)
Nexus Repository 3 3.17.0 < 3.95.0
