NONE · 0

CVE-2026-17594

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a deleg...

Vulnerability Description

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could create a repository of a different, unauthorized format, because authorization was checked against one request field while a separate, attacker-controlled field determined the repository format actually created. This does not affect the anonymous user, which cannot hold this privilege by default. Fixed in version 3.95.0.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-17594?

CVE-2026-17594 is a documented vulnerability. Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a deleg...

How severe is CVE-2026-17594?

CVSS scoring is not yet available for CVE-2026-17594. Check NVD for updates.

Is there a patch for CVE-2026-17594?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.