Wildcard Privilege Modification in Sonatype Nexus Repository
CVE-2026-17601

8.9HIGH

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
7 August 2026

What is CVE-2026-17601?

A critical security flaw allows users with permission to update privilege definitions in Sonatype Nexus Repository to improperly broaden their roles. This vulnerability enables individuals to modify a wildcard privilege assigned to their role, potentially granting them unauthorized access to administrative capabilities without additional checks, posing significant security risks to users and the system as a whole.

Affected Version(s)

Nexus Repository 3 3.19.0 < 3.95.0

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Beni Saprulah (HackerOne: https://hackerone.com/bebensap, LinkedIn: https://www.linkedin.com/in/beni-saprulah)
.