Password Change Vulnerability in Nexus Repository by Sonatype
CVE-2026-17599

6.9MEDIUM

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
7 August 2026

What is CVE-2026-17599?

Nexus Repository 3 has a security weakness in its password change feature, which can be exploited during the onboarding phase. Specifically, an endpoint intended for changing the administrator password does not adequately verify if onboarding is active, allowing unauthorized account holders with nexus:* permissions to change the administrator's password outside the intended context. This security lapse means that existing user sessions remain active even after a password change, increasing the risk of unauthorized access and control.

Affected Version(s)

Nexus Repository 3 3.17.0 < 3.95.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kjcao
.