What is CVE-2026-17598?
CVE-2026-17598: A vulnerability was identified in Sonatype Nexus Repository 3 where internal configuration keys were not properly filtered from user-supplied task properties in the administrative UI when creating or updating a scheduled task. An account with permission to create at least one scheduled task type could exploit this by supplying a crafted property value. It is strongly recommended to apply the security update provided by Sonatype immediately.
Azərbaycanca: CVE-2026-17598: Sonatype Nexus Repository 3-ün inzibati interfeysində planlaşdırılmış tapşırıq (scheduled task) yaradarkən istifadəçi tərəfindən verilən xassə dəyərlərində daxili konfiqurasiya açarlarının (internal configuration keys) düzgün filtrasiya edilməməsi boşluğu aşkarlanıb. Bu, ən azı bir tapşırıq tipi yaratmaq icazəsi olan hesab sahibinə xüsusi hazırlanmış dəyərlər vasitəsilə sistemə təsir etməyə imkan verə bilər. İstismar riskini azaltmaq üçün təcili olaraq Sonatype tərəfindən təqdim edilən təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
FAQ2
In which interface of Sonatype Nexus Repository 3 was CVE-2026-17598 discovered?
This vulnerability was identified in the administrative UI when creating or updating a scheduled task.
What permission does an attacker need to exploit CVE-2026-17598?
The attacker needs an account with permission to create at least one scheduled task type.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.