← Back to CVE List
Vulnerability Intelligence Report
Nexus Repository 3 - Session Not Invalidated on User Account Deletion or Deactivation

CVE-2026-17600

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already logged in at the time of one of these actions could continue using their existing session to interact with the repository as though the account were still active, until that session independently expired. Depending on the permissions previously held, this could allow continued unauthorized access to read, modify, or delete repository content after access was intended to be revoked.

No Active Exploit Signals
CVSS Base Score
8.7
HIGH
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-613 ↗CWE-613 Insufficient Session Expiration

Affected Products & Versions

Vendor Product Affected Versions
Sonatype Nexus Repository 3 3.0.0 < 3.95.0 (affected)
Sonatype 1.1.0 <= 3.3 (affected)
Sonatype 2.6.0-01 <= 3.88.0-08 (affected)
Sonatype 3.89.0-09 < 3.95.0 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthoritySonatype Inc. · Vendor · USA
Reserved2026-07-27T16:30:41
Published2026-08-07T16:07:42
Last Updated2026-08-07T18:07:54

LINK COPIED TO CLIPBOARD