CVE-2026-17596 Details
Description
Nexus Repository 3 was found to be vulnerable to stored cross-site scripting (XSS). A user with the nexus:blobstores:create or nexus:blobstores:update permission could set a blob store name containing malicious script content, which would later execute in the browser of another user viewing system health-check status. This issue has been fixed in version 3.95.0.
A stored cross-site scripting vulnerability has been identified in Sonatype Nexus Repository 3, affecting versions 3.16.0 through 3.94.x. The issue allows users with the 'nexus:blobstores:create' or 'nexus:blobstores:update' permission to inject malicious scripts into blob store names. These scripts are executed in the browsers of users, such as administrators, who view the system health-check status where the blob store name is displayed. This could enable an attacker to perform actions on behalf of the higher-privileged user.
Users are advised to upgrade to Sonatype Nexus Repository 3 version 3.95.0 or later. For those unable to upgrade immediately, it is recommended to restrict the 'nexus:blobstores:create' and 'nexus:blobstores:update' permissions to trusted administrators only and to avoid viewing system health-check status while untrusted blob store names may be present.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html | Sonatype | Release Notes |
| https://support.sonatype.com/hc/en-us/articles/53871280401555/ | Sonatype | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | Sonatype |
Affected Products
| Product | Versions |
|---|---|
| sonatype nexus repository manager | >= 3.16.0, < 3.95.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | Initial Analysis | [email protected] |
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 7, 2026 | New CVE Received | Sonatype |