AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-17600

HIGH · CVSS 8.7 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

Sonatype Nexus Repository 3 is vulnerable due to its failure to immediately terminate active user sessions or revoke cached permissions when an account is deleted, deactivated, or its password is changed. This flaw allows an attacker with an active session to maintain unauthorized access to repository content, potentially leading to data breaches or unauthorized modifications. Organizations using Nexus Repository 3 should prioritize addressing this vulnerability to mitigate the risk of unauthorized access and ensure proper session management.

CVE
CVE-2026-17600
Severity
HIGH
CVSS
8.7
EPSS
0.21%

Original NVD Description

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing session to interact with the repository as though the account were still active, until that session independently expired. Depending on the permissions previously held, this could allow continued unauthorized access to read, modify, or delete repository content after access was intended to be revoked.