CVE-2026-17601

Sonatype · Nexus Repository 3

A missing authorization vulnerability in Sonatype Nexus Repository 3 allows authenticated users with privilege update permissions to escalate their access to full administrative rights.

Executive summary

A critical privilege escalation vulnerability in Sonatype Nexus Repository 3 could allow an authenticated user to gain full administrative control over the application.

Vulnerability

The application fails to perform adequate authorization checks when a user modifies wildcard privilege definitions. An authenticated user with existing permissions to update privileges can manipulate these definitions to grant themselves unauthorized elevated access, including full administrative privileges.

Business impact

Successful exploitation results in a complete compromise of the repository management system. Because this vulnerability allows an attacker to gain administrative control, it poses a severe risk to the integrity and availability of software artifacts, potentially enabling supply chain attacks or the unauthorized exfiltration of sensitive proprietary code. The CVSS score of 8.9 highlights the high severity of this flaw despite the requirement for prior authentication.

Remediation

Immediate Action: Update Sonatype Nexus Repository 3 to version 3.95.0 or later as specified in the vendor release notes.

Proactive Monitoring: Review audit logs for suspicious modifications to privilege definitions, specifically looking for wildcard privilege changes initiated by non-admin accounts.

Compensating Controls: Restrict administrative access to the Nexus interface by implementing network-level access controls or VPN requirements to limit the exposure of the management console.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security risk for organizations relying on Nexus Repository 3 for build and artifact management. Administrators must prioritize the upgrade to version 3.95.0 to eliminate the possibility of unauthorized privilege escalation and ensure the continued integrity of the development pipeline.