CVE-2026-17594

HIGH CVSS 4.0: 8.2 EPSS 0.24%
Updated Aug 07, 2026
Nexus
Parameter Value
CVSS 8.2 (HIGH)
Affected Versions 3.0.0 — 3.94.
Fixed In 3.95.0
Type CWE-863 (Incorrect Authorization)
Vendor Nexus
Public PoC No

Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could create a repository of a different, unauthorized format, because authorization was checked against one request field while a separate, attacker-controlled field determined the repository format actually created. This does not affect the anonymous user, which cannot hold this privilege by default.

Fixed in version 3.95.0.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
None
No disruption

CVSS Vector v4.0