Skip to content

Sonatype vulnerabilities

2 CVEs tracked

In our reporting, Sonatype appears in the context of authentication and access control issues, specifically with the Nexus Repository 3 product. Key incidents include a session management flaw tracked as CVE-2026-17600, where active sessions are not terminated upon account changes, and CVE-2026-17598, which involves insufficient filtering of internal configuration keys via scheduled tasks. The vendor is also mentioned alongside findings that enterprise applications carry 4.31 times more critical and high vulnerabilities. Defenders should immediately review session invalidation mechanisms for deactivated accounts (CVE-2026-17600) and enhance auditing for roles with task creation permissions (CVE-2026-17598).

This vendor's CVEs2

This hub is built from skopnix's own reporting on Sonatype: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.