AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17598

MEDIUM · CVSS 5.3 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Sonatype Nexus Repository 3 is vulnerable due to inadequate filtering of internal configuration keys in user-supplied task properties, allowing users with permission to create scheduled tasks to overwrite existing task configurations. This could lead to unintended modifications of critical tasks, potentially disrupting repository operations. Organizations using Nexus Repository 3 should prioritize this issue to mitigate risks associated with task misconfigurations.

CVE
CVE-2026-17598
Severity
MEDIUM
CVSS
5.3
EPSS
0.25%

Original NVD Description

Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the system to overwrite the configuration of an unrelated, existing task instead of creating a new one.