SQL Injection Vulnerability in Nexus Repository by Sonatype
CVE-2026-17603
8.7HIGH
What is CVE-2026-17603?
A vulnerability exists in Nexus Repository where insufficient restrictions on HikariCP connection-pool properties allow users with the nx-datastores-update permission to set the connectionInitSql property. This can lead to executing arbitrary SQL commands on the database with every new connection. In cases using the default H2 backend, this can be exploited to potentially gain remote code execution capabilities under the Nexus process user.
Affected Version(s)
Nexus Repository 3 3.20.0 < 3.95.0
