Nexus Repository 3 - Unverified Onboarding State on change-admin-password Endpoint
Summary
| CVE | CVE-2026-17599 |
|---|---|
| State | PUBLISHED |
| Assigner | Sonatype |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-07 17:17:00 UTC |
| Updated | 2026-08-07 19:17:39 UTC |
| Description | Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change. |
Risk And Classification
Primary CVSS: v4.0 6.9 MEDIUM from 103e4ec9-0a87-450b-af77-479448ddef11
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-620 | CWE-620 CWE-620 Unverified Password Change
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 103e4ec9-0a87-450b-af77-479448ddef11 | Secondary | 6.9 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6.9 | MEDIUM | CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
HighUser Interaction
NoneConfidentiality
NoneIntegrity
HighAvailability
NoneSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Sonatype | Nexus Repository 3 | affected 3.17.0 3.95.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html | 103e4ec9-0a87-450b-af77-479448ddef11 | help.sonatype.com | |
| support.sonatype.com/hc/en-us/articles/53884654627475 | 103e4ec9-0a87-450b-af77-479448ddef11 | support.sonatype.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: kjcao (en)
There are currently no legacy QID mappings associated with this CVE.