AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17596

MEDIUM · CVSS 6.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Nexus Repository 3 is susceptible to stored cross-site scripting (XSS), allowing users with specific permissions to inject malicious scripts into blob store names. This vulnerability can lead to the execution of harmful scripts in the browsers of other users accessing system health-check status, potentially compromising user data and session integrity. Organizations using Nexus Repository 3 should prioritize upgrading to version 3.95.0 to mitigate this risk.

CVE
CVE-2026-17596
Severity
MEDIUM
CVSS
6.3
EPSS
0.24%

Original NVD Description

Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status. This issue has been fixed in version 3.95.0.