Sonatype Nexus Repository 3 Community Edition and Pro contain a high-severity authorization flaw tracked as CVE-2026-17594 that lets a user with delegated repository-admin rights for one repository format create a repository in a different, unauthorized format. The issue affects versions 3.0.0 through 3.94.x and stems from the repository-creation workflow validating permissions against one request field while using a separate attacker-controlled field to determine the repository format actually created. The vulnerability is remotely exploitable, mapped to CWE-863, and carries a CVSS 4.0 score of 8.2.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On August 7, 2026, the CVE record for CVE-2026-17594 was published, describing a remotely exploitable incorrect authorization flaw affecting Sonatype Nexus Repository 3 versions 3.0.0 through 3.94.x. The entry assigned the issue a CVSS 4.0 score of 8.2 and mapped it to CWE-863.
A GitHub pull request published proof-of-concept exploitation details and a Nuclei template for CVE-2026-17594, showing successful unauthorized raw repository creation on Nexus Repository 3.94.1-06 and failure to reproduce on 3.95.0-07. The material documented the vulnerable RepositoryUiService.create() flow and included sample exploit and validation output.
Sonatype fixed CVE-2026-17594, an authorization bypass in Nexus Repository 3 that lets a delegated repository admin create a repository of an unauthorized format. The remediation is to upgrade to Nexus Repository Manager 3.95.0 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.