What is CVE-2026-17603?
CVE-2026-17603 vulnerability in Nexus Repository 3 allows insufficiently restricted HikariCP connection-pool properties via the DataStore configuration API. A user with 'nx-datastores-update' permission can set the 'connectionInitSql' property to execute arbitrary SQL on the database. Immediate access control review and patching are recommended for affected systems.
Azərbaycanca: CVE-2026-17603 zəifliyi Nexus Repository 3-də DataStore konfiqurasiya API-si vasitəsilə HikariCP bağlantı hovuzunun 'connectionInitSql' xüsusiyyətini təyin etməyə imkan verir. 'nx-datastores-update' icazəsinə malik istifadəçi bunu istismar edərək verilənlər bazasında ixtiyari SQL əmrləri icra edə bilər. Təsirə məruz qalan sistemlərdə dərhal giriş nəzarətlərini yoxlamaq və müvafiq yamağı tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89
FAQ2
What permission is required to exploit CVE-2026-17603?
The 'nx-datastores-update' permission is required to exploit this vulnerability.
What operation can be performed on the database through CVE-2026-17603?
Arbitrary SQL commands can be executed on the database by setting the 'connectionInitSql' property.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.