What is CVE-2026-17596?
Nexus Repository 3 contains a stored XSS vulnerability where a user with specific permissions can set a blob store name with malicious script. This script executes in the browser of another user viewing the system. It is recommended to apply updates and review blob store creation/update permissions.
Azərbaycanca: Nexus Repository 3-də saxlanılan XSS zəifliyi aşkarlanıb. Xüsusi icazələrə malik istifadəçi blob store adına zərərli skript yerləşdirə bilər ki, bu da digər istifadəçinin brauzerində icra olunur. Mühitinizi yeniləmək və blob store yaratma/redaktə icazələrini nəzərdən keçirmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What permissions must an attacker have to exploit CVE-2026-17596?
The attacker must have specific permissions in Nexus Repository 3 that allow modifying the blob store name, namely blob store creation or update permissions.
What measures should be taken to protect against CVE-2026-17596?
It is recommended to apply updates and review blob store creation/update permissions to ensure they are granted only to trusted users.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.