AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17594

HIGH · CVSS 8.2 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x are vulnerable due to an incorrect authorization flaw that allows users with delegated repository-admin privileges to create repositories in unauthorized formats. This misconfiguration can lead to unauthorized access and manipulation of repository data, posing a significant risk to organizations relying on these versions for secure artifact management. Users of affected versions should prioritize upgrading to version 3.95.0 to mitigate this high-severity vulnerability.

CVE
CVE-2026-17594
Severity
HIGH
CVSS
8.2
EPSS
0.24%

Original NVD Description

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could create a repository of a different, unauthorized format, because authorization was checked against one request field while a separate, attacker-controlled field determined the repository format actually created. This does not affect the anonymous user, which cannot hold this privilege by default. Fixed in version 3.95.0.