CVE-2026-17598: Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the system to overwrite the configuration of an unrelated, existing task instead of creating a new one.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17598?
CVE-2026-17598 has a risk score of 44, indicating a significant security concern.
How do I fix CVE-2026-17598?
To fix CVE-2026-17598, update to the latest version of Sonatype Nexus Repository 3 provided by Sonatype.
What software is affected by CVE-2026-17598?
CVE-2026-17598 affects Sonatype Nexus Repository 3.
What kind of vulnerability is CVE-2026-17598?
CVE-2026-17598 is classified as an improper input validation vulnerability.
Who is at risk from CVE-2026-17598?
Accounts with permissions to create scheduled tasks in Sonatype Nexus Repository 3 are at risk from CVE-2026-17598.