SQL Injection Vulnerability in Nexus Repository by Sonatype
CVE-2026-17603

8.7HIGH

Key Information:

Vendor

Sonatype

Vendor
CVE Published:
7 August 2026

What is CVE-2026-17603?

A vulnerability exists in Nexus Repository where insufficient restrictions on HikariCP connection-pool properties allow users with the nx-datastores-update permission to set the connectionInitSql property. This can lead to executing arbitrary SQL commands on the database with every new connection. In cases using the default H2 backend, this can be exploited to potentially gain remote code execution capabilities under the Nexus process user.

Affected Version(s)

Nexus Repository 3 3.20.0 < 3.95.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Shreyas Chavhan (@shreyaschavhan)
.