{"id":"CVE-2026-17594","title":"Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface","summary":"Nexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scope…","severity":"medium","cvss":4.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-863"],"vendor":"sonatype","product":"nexus_repository_manager","affected":["nexus_repository_manager >= 3.0.0, < 3.95.0"],"patched":["nexus_repository_manager 3.95.0"],"published":"2026-08-07","updated":"2026-09-22","sourceUpdated":"2026-09-22T17:01:40.453","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-17594","references":[{"url":"https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html","label":"103e4ec9-0a87-450b-af77-479448ddef11"},{"url":"https://support.sonatype.com/hc/en-us/articles/53851569407891/","label":"103e4ec9-0a87-450b-af77-479448ddef11"}],"tags":["nvd","exploit-available"],"epss":0.00742,"epssPercentile":0.52662,"exploits":{"nuclei":["CVE-2026-17594"],"checkedAt":"2026-09-25T08:20:51.588Z"},"exploitAvailable":true,"ingestedAt":"2026-09-22T17:07:07.347Z","slug":"CVE-2026-17594","body":"## Overview\n\nNexus Repository 3 CE/Pro versions 3.0.0 through 3.94.x contain an incorrect authorization vulnerability (CWE-863) in the repository-creation user interface. An individual user account holding a delegated repository-admin privilege scoped to a specific repository format could create a repository of a different, unauthorized format, because authorization was checked against one request field while a separate, attacker-controlled field determined the repository format actually created. This does not affect the anonymous user, which cannot hold this privilege by default. Fixed in version 3.95.0.\n\n## Affected\n\n- `nexus_repository_manager >= 3.0.0, < 3.95.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `nexus_repository_manager 3.95.0`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":27,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}