๐Ÿ” CVE Alert

CVE-2026-17601

UNKNOWN 0.0

Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.

CWE CWE-862
Vendor sonatype
Product nexus repository 3
Published Aug 7, 2026
Stay Ahead of the Next One

Get instant alerts for sonatype nexus repository 3

Be the first to know when new unknown vulnerabilities affecting sonatype nexus repository 3 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Sonatype / Nexus Repository 3
3.19.0 < 3.95.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
help.sonatype.com: https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html support.sonatype.com: https://support.sonatype.com/hc/en-us/articles/53889365883539/

Credits

Beni Saprulah (HackerOne: https://hackerone.com/bebensap, LinkedIn: https://www.linkedin.com/in/beni-saprulah)