CVE-2026-17599
Received Received - Intake

Nexus Repository 3 Password Change Authentication Bypass

Vulnerability report for CVE-2026-17599, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-07

Last updated on: 2026-08-07

Assigner: Sonatype

Description

Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-07
Last Modified
2026-08-07
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
sonatype nexus_repository 3.95.0
sonatype nexus_repository to 3.94.x (inc)
sonatype nexus_repository 3

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-620 When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Nexus Repository 3 had an endpoint that allowed changing the administrator password during initial setup. This endpoint did not check if onboarding was still active, only requiring a local onboarding file. Attackers with nexus:* permissions could exploit this to reset the admin password outside the intended flow and retain unauthorized access since sessions were not invalidated.

Detection Guidance

Check Nexus Repository 3 versions between 3.17.0 and 3.94.x. Verify if the change-admin-password endpoint is accessible without proper onboarding validation. Review logs for unauthorized password change attempts or persistent sessions after admin password updates.

Impact Analysis

An attacker could gain administrative control over the Nexus Repository by resetting the admin password. This allows full access to system configurations, repositories, and sensitive data. Existing sessions remain active, enabling persistent unauthorized access even after the password change.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Unauthorized administrative access may result in data breaches, non-compliance with access control policies, and potential regulatory penalties due to inadequate security measures.

Mitigation Strategies

Upgrade Nexus Repository 3 to version 3.95.0 or later immediately. Remove or restrict nexus:* permissions for non-admin accounts. Monitor for unauthorized admin password changes and invalidate all active admin sessions after any password update.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17599. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart