← All CVEs NewScan detects
high

CVE-2026-17601

Nexus Repository 3 wildcard-privilege self-escalation to administrator

Severity
high
Affected product
Nexus Repository
Affected versions
Nexus Repository ≥ 3.19.0, < 3.95.0
Fixed in
Nexus Repository 3.95.0
Added to NewScan
2026-08-23
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Nexus Repository from its response and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-23 with the Nexus fingerprint (tech_signatures header.server row on the Server: Nexus/x.y.z-zz banner, measured against the training/cve vulhub env - every response carries it, 200s and 404s alike). Sonatype's advisory (support.sonatype.com, 2026-08-07): affected 3.19.0 through 3.94.x, fixed 3.95.0; a user permitted to update privilege definitions can widen a wildcard privilege already assigned to their own role into full admin. Range is x.y.z-granular, which is exactly what the fingerprint's capture yields (the -zz build suffix is deliberately not captured - see that row's note; version_in_range cannot see it, the NetScaler D117 wall). The measured env (3.14.0-04) sits below the ge bound and is correctly unflagged. The OTHER nine ids of the 2026-08-07 window (17600, 17595, 17594, 17593, 17599, 17598, 17596, 17597, 14644) share this fingerprint but each needs its own advisory range before a row - most are authenticated-user privilege bugs only ever version-matched (D87), and 17597 is the OOB SSRF that stays a collaborator item.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →