What is CVE-2026-17597?
CVE-2026-17597 is a Server-Side Request Forgery (SSRF) vulnerability in the email configuration verification feature of Nexus Repository 3. A user with the 'nexus-settings-update' permission can exploit this by submitting arbitrary host and port values, forcing the server to make unintended outbound requests. Upgrading to the latest version of Nexus Repository 3 is recommended to mitigate this issue.
Azərbaycanca: CVE-2026-17597: Nexus Repository 3-də email konfiqurasiyasının doğrulanması funksiyasında Server-Side Request Forgery (SSRF) zəifliyi aşkar edilib. 'nexus-settings-update' icazəsinə malik istifadəçi ixtiyari host və port daxil edərək serveri xarici resurslara sorğu göndərməyə məcbur edə bilər. Bu zəifliyi aradan qaldırmaq üçün Nexus Repository 3-ü ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
What permission is required to exploit the CVE-2026-17597 vulnerability?
An attacker needs the 'nexus-settings-update' permission to exploit this SSRF vulnerability.
What is the recommended mitigation for CVE-2026-17597?
Upgrading Nexus Repository 3 to the latest version is recommended to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.