CVE-2026-17600: Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing session to interact with the repository as though the account were still active, until that session independently expired. Depending on the permissions previously held, this could allow continued unauthorized access to read, modify, or delete repository content after access was intended to be revoked.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17600?
The severity of CVE-2026-17600 is rated at 51, indicating it poses a noteworthy security risk.
How do I fix CVE-2026-17600?
To fix CVE-2026-17600, ensure that user sessions are terminated and permissions revoked immediately upon account deletion or deactivation.
What types of accounts are affected by CVE-2026-17600?
CVE-2026-17600 affects user accounts in Sonatype Nexus Repository 3 that are deleted, deactivated, or have their passwords changed.
What potential risks are associated with CVE-2026-17600?
The risks associated with CVE-2026-17600 include unauthorized access and actions by users whose accounts have been deactivated or deleted.
When was CVE-2026-17600 published?
CVE-2026-17600 was published on August 7, 2026.