HIGH 8.9 NVD
CVE-2026-17601
A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions th
A user holding a permission to update privilege definitions could modify a wildcard privilege already assigned to their own role to grant broader permissions than they were authorized to hold, including full administrative access, without any additional authorization check or role reassignment.
References
- https://help.sonatype.com/en/sonatype-nexus-repository-3-95-0-release-notes.html
- https://support.sonatype.com/hc/en-us/articles/53889365883539/
This high severity vulnerability with a CVSS score of 8.9 was published on 2026-08-07 via NVD.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.