CVE-2026-17599
CVE-2026-17599 is a medium-severity vulnerability with a CVSS 4.0 base score of 6.9. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-620.
Key facts
- Severity: Medium (CVSS 4.0 base score 6.9)
- EPSS exploit prediction: 0% (22nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-620
- Published:
- Last modified:
Description
Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change.
Frequently asked questions
- What is CVE-2026-17599?
- Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change.
- How severe is CVE-2026-17599?
- CVE-2026-17599 has a CVSS 4.0 base score of 6.9, rated medium severity.
- Is CVE-2026-17599 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (22nd percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-17599?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-17599 published?
- CVE-2026-17599 was published on 2026-08-07.
References
- https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html
- https://support.sonatype.com/hc/en-us/articles/53884654627475/
Other CWE-620 vulnerabilities
- CVE-2024-20419 — Critical (CVSS 10.0): A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an…
- CVE-2025-1107 — Critical (CVSS 9.9): Unverified password change vulnerability in Janto, versions prior to r12. This could allow an unauthenticated attacker…
- CVE-2024-33699 — Critical (CVSS 9.9): The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers…
- CVE-2026-15964 — Critical (CVSS 9.8): The Single Sign On For TNG plugin for WordPress is vulnerable to Authentication Bypass via unauthenticated password…
- CVE-2026-12692 — Critical (CVSS 9.8): Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This…
- CVE-2025-63362 — Critical (CVSS 9.8): Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage…