CVE-2026-17601
Nexus Repository 3 - Wildcard Privilege Update Self-Escalation to Administrator
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.
| CWE | CWE-862 |
| Vendor | sonatype |
| Product | nexus repository 3 |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for sonatype nexus repository 3
Be the first to know when new unknown vulnerabilities affecting sonatype nexus repository 3 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Sonatype / Nexus Repository 3
3.19.0 < 3.95.0
References
Credits
Beni Saprulah (HackerOne: https://hackerone.com/bebensap, LinkedIn: https://www.linkedin.com/in/beni-saprulah)