CVE-2026-17593: CWE-470 Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection) in Sonatype Nexus Repository
An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because unrecognized entries were persisted and re-evaluated on every realm load via a legacy code path, this could result in unintended code executing inside the Nexus Repository process, and in some cases a persistent authentication lockout that was not visible through the administrative UI.
AI Analysis
Technical Summary
This vulnerability arises from Nexus Repository 2.8.0 allowing accounts with nexus:settings:update permission to submit arbitrary values as realm identifiers through an internal configuration API. The API does not validate these identifiers against registered realms, causing unrecognized entries to be persisted and re-evaluated on each realm load via legacy code paths. This unsafe reflection (CWE-470) can result in unintended code execution inside the Nexus Repository process and, in some cases, persistent authentication lockout that is not visible through the administrative interface.
Potential Impact
Exploitation requires an account with nexus:settings:update permission. Successful exploitation can lead to arbitrary code execution within the Nexus Repository process, potentially compromising the system. Additionally, it can cause persistent authentication lockouts that administrators cannot detect via the UI, impacting availability and management.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to accounts with nexus:settings:update permission and monitor for suspicious activity related to realm configuration changes.
CVE-2026-17593: CWE-470 Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection) in Sonatype Nexus Repository
Description
An account holding the nexus:settings:update permission in Nexus Repository 3 (or the equivalent nexus:settings permission in the legacy Nexus Repository 2) could submit arbitrary values as realm identifiers through an internal configuration API that did not validate them against the set of registered realms. Because unrecognized entries were persisted and re-evaluated on every realm load via a legacy code path, this could result in unintended code executing inside the Nexus Repository process, and in some cases a persistent authentication lockout that was not visible through the administrative UI.
CVSS v4.0
Score 7.2high
Affected software
pkg:maven/a/sonatype-nexus-repository-managercpe:2.3:a:sonatype:nexus_repository_manager:2.8.0:*:*:*:*:*:*:*cpe:2.3:a:sonatype:nexus_repository_manager:2.8.1:*:*:*:*:*:*:*cpe:2.3:a:sonatype:nexus_repository_manager:2.9:*:*:*:*:*:*:*cpe:2.3:a:sonatype:nexus_repository_manager:2.9.1:*:*:*:*:*:*:*cpe:2.3:a:sonatype:nexus_repository_manager:2.9.2:*:*:*:*:*:*:*cpe:2.3:a:sonatype:nexus_repository_manager:2.10:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from Nexus Repository 2.8.0 allowing accounts with nexus:settings:update permission to submit arbitrary values as realm identifiers through an internal configuration API. The API does not validate these identifiers against registered realms, causing unrecognized entries to be persisted and re-evaluated on each realm load via legacy code paths. This unsafe reflection (CWE-470) can result in unintended code execution inside the Nexus Repository process and, in some cases, persistent authentication lockout that is not visible through the administrative interface.
Potential Impact
Exploitation requires an account with nexus:settings:update permission. Successful exploitation can lead to arbitrary code execution within the Nexus Repository process, potentially compromising the system. Additionally, it can cause persistent authentication lockouts that administrators cannot detect via the UI, impacting availability and management.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to accounts with nexus:settings:update permission and monitor for suspicious activity related to realm configuration changes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Sonatype
- Date Reserved
- 2026-07-27T16:29:50.535Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a760745bf8831d5399dca71
Added to database: 08/07/2026, 16:26:45 UTC
Last enriched: 08/07/2026, 16:41:43 UTC
Last updated: 08/07/2026, 20:05:14 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.