CVE-2026-17596Disclosure(sonatype / nexus_repository_manager)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sonatype nexus_repository_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status. This issue has been fixed in version 3.95.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nexus_repository_manager

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
nexus_repository_manager

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-11: 1Patch / Workaround · 2026-08-11: 108-11
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • Youssef (s3c)@s3c_krd
    Disclosure

    Proud to share this research with http://Cyberscope.krd — I identified and responsibly disclosed a security vulnerability in Sonatype Nexus. The issue was patched by the Sonatype team, and I’ve been officially credited with: 📌 CVE-2026-17596 https://www.cve.org/cverecord?id=CVE-2026-17596

    Post summary

    The author reports discovering and responsibly disclosing CVE-2026-17596 in Sonatype Nexus, which was patched by the vendor and for which the researcher received official credit.

    0001141.3K
    10.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsonatypenexus_repository_manager---

Explore more