What is CVE-2026-17593?
CVE-2026-17593 is a vulnerability in Nexus Repository manager where accounts with `nexus:settings:update` permission can submit arbitrary values as realm identifiers via an internal API lacking validation against registered realms. This could allow unvalidated identifiers to be registered and potentially be exploited to bypass security restrictions. It is recommended to restrict permissions and validate API inputs on affected systems.
Azərbaycanca: CVE-2026-17593, Nexus Repository menecerində `nexus:settings:update` icazəsinə malik hesabların reallm identifikatorlarını yoxlamayan daxili API vasitəsilə ixtiyari dəyərlər təqdim etməsinə imkan verən zəiflikdir. Bu, təsdiqlənməmiş identifikatorların qeydiyyatdan keçməsinə səbəb ola bilər və təhlükəsizlik məhdudiyyətlərini yan keçmək üçün istismar edilə bilər. Təsirə məruz qalan sistemlərdə icazələri məhdudlaşdırmaq və API girişini yoxlamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
What specific permission is required to exploit CVE-2026-17593?
An attacker must have an account with the `nexus:settings:update` permission to exploit this vulnerability.
Which product is affected by CVE-2026-17593?
This vulnerability affects the Nexus Repository manager product.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.