CVE-2026-17598EPSS p12.3%
CVE-2026-17598CVE-2026-17598
sonatype / nexus_repository_manager
Description
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the system to overwrite the configuration of an unrelated, existing task instead of creating a new one.
Scoring
| CVSS | 4.9 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |
| EPSS | 0.23% probability of exploitation · percentile 12.3% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-22 |