CVE-2026-17601
Nexus Repository 3 wildcard-privilege self-escalation to administrator
- Severity
- high
- Affected product
- Nexus Repository
- Affected versions
- Nexus Repository ≥ 3.19.0, < 3.95.0
- Fixed in
- Nexus Repository 3.95.0
- Added to NewScan
- 2026-08-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Nexus Repository from its response and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-23 with the Nexus fingerprint (tech_signatures header.server row on the Server: Nexus/x.y.z-zz banner, measured against the training/cve vulhub env - every response carries it, 200s and 404s alike). Sonatype's advisory (support.sonatype.com, 2026-08-07): affected 3.19.0 through 3.94.x, fixed 3.95.0; a user permitted to update privilege definitions can widen a wildcard privilege already assigned to their own role into full admin. Range is x.y.z-granular, which is exactly what the fingerprint's capture yields (the -zz build suffix is deliberately not captured - see that row's note; version_in_range cannot see it, the NetScaler D117 wall). The measured env (3.14.0-04) sits below the ge bound and is correctly unflagged. The OTHER nine ids of the 2026-08-07 window (17600, 17595, 17594, 17593, 17599, 17598, 17596, 17597, 14644) share this fingerprint but each needs its own advisory range before a row - most are authenticated-user privilege bugs only ever version-matched (D87), and 17597 is the OOB SSRF that stays a collaborator item.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →