CVE-2026-17599

Source
https://cve.org/CVERecord?id=CVE-2026-17599
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17599.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-17599
Downstream
MINI (2)
Published
2026-08-07T16:07:42Z
Modified
2026-09-24T03:45:12Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint
Details

Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change.

Database specific
{
    "cna_assigner":  "Sonatype",
    "cwe_ids":  [
        "CWE-620"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17599.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "3.17.0"
                },
                {
                    "fixed":  "3.95.0"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/sonatype/nexus-public

Affected ranges

Type
GIT
Repo
https://github.com/sonatype/nexus-public
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:sonatype:nexus_repository_manager:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "3.17.0"
        },
        {
            "fixed":  "3.95.0"
        }
    ],
    "source":  "CPE_RANGE"
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17599.json"