[NEW] [high] Sonatype Nexus Repository Manager: Multiple vulnerabilities
A remote, authenticated attacker can exploit multiple vulnerabilities in Sonatype Nexus Repository Manager to disclose or manipulate data, execute code, or escalate privileges.
CSIRTS triage
- What
- Multiple vulnerabilities allow authenticated remote attackers to disclose or manipulate data, execute code, or escalate privileges.
- Who is affected
- Deployments of Nexus Repository Manager with authenticated users or weak access controls are affected.
- Urgency
- High severity with remote code execution and privilege escalation; requires urgent patching despite lack of reported exploitation.
- Action
- Patch Nexus Repository Manager to latest version immediately and review user access controls and repository permissions.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Nexus Repository Manager
Get an email when a new Nexus Repository Manager advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2713
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-146440.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175930.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175940.61% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175950.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175960.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175970.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175980.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-175990.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-176000.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-176010.21% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-14644 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17593 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17594 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17595 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17596 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17597 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17598 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17599 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17600 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17601 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-17603 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownCVE-2026-17603: Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties cou…nvd
- unknownCVE-2026-17601: A user holding a permission to update privilege definitions could modify a wildcard privilege …nvd
- unknownCVE-2026-17600: Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or rev…nvd
- unknownCVE-2026-17599: Nexus Repository 3 contained an endpoint used to change the administrator account password dur…nvd
- unknownCVE-2026-17598: Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supp…nvd
- unknownCVE-2026-17597: Nexus Repository 3 contains a Server-Side Request Forgery (SSRF) vulnerability in the email co…nvd
- unknownCVE-2026-17596: Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user wit…nvd
- unknownCVE-2026-17595: Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An accoun…nvd
- unknownCVE-2026-17594: Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vul…nvd
- unknownCVE-2026-17593: An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivale…nvd
- unknownCVE-2026-14644: Nexus Repository 3 contained a privilege escalation vulnerability in the REST privileges API. …nvd
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] Linux Kernel: Multiple vulnerabilities2026-08-25
- medium[NEW] [medium] libTIFF: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Contao: Multiple Vulnerabilities2026-08-25
- medium[NEW] [medium] Django: Multiple Vulnerabilities2026-08-25
- high[NEW] [high] Red Hat Enterprise Linux (Apicurio Registry): Multiple Vulnerabilities2026-08-25