๐Ÿ” CVE Alert

CVE-2026-17600

UNKNOWN 0.0

Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing session to interact with the repository as though the account were still active, until that session independently expired. Depending on the permissions previously held, this could allow continued unauthorized access to read, modify, or delete repository content after access was intended to be revoked.

CWE CWE-613
Vendor sonatype
Product nexus repository 3
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for sonatype nexus repository 3

Be the first to know when new unknown vulnerabilities affecting sonatype nexus repository 3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Sonatype / Nexus Repository 3
3.0.0 < 3.95.0
Sonatype /
1.1.0 โ‰ค 3.3
Sonatype /
2.6.0-01 โ‰ค 3.88.0-08
Sonatype /
3.89.0-09 < 3.95.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
help.sonatype.com: https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html support.sonatype.com: https://support.sonatype.com/hc/en-us/articles/53888843674003/

Credits

Sanjok Karki (thesanjok) - https://sanjokkarki.com.np