Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation
Summary
| CVE | CVE-2026-17600 |
|---|---|
| State | PUBLISHED |
| Assigner | Sonatype |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-07 17:17:00 UTC |
| Updated | 2026-08-07 19:17:40 UTC |
| Description | Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing session to interact with the repository as though the account were still active, until that session independently expired. Depending on the permissions previously held, this could allow continued unauthorized access to read, modify, or delete repository content after access was intended to be revoked. |
Risk And Classification
Primary CVSS: v4.0 8.7 HIGH from 103e4ec9-0a87-450b-af77-479448ddef11
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-613 | CWE-613 CWE-613 Insufficient Session Expiration
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 103e4ec9-0a87-450b-af77-479448ddef11 | Secondary | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
LowUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Sonatype | Nexus Repository 3 | affected 3.0.0 3.95.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html | 103e4ec9-0a87-450b-af77-479448ddef11 | help.sonatype.com | |
| support.sonatype.com/hc/en-us/articles/53888843674003 | 103e4ec9-0a87-450b-af77-479448ddef11 | support.sonatype.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Sanjok Karki (thesanjok) - https://sanjokkarki.com.np (en)
There are currently no legacy QID mappings associated with this CVE.