Description
Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the system to overwrite the configuration of an unrelated, existing task instead of creating a new one.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 07 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sonatype Nexus Repository 3 did not properly filter internal configuration keys from user-supplied task properties when creating or updating a scheduled task through the administrative UI. An account holding permission to create at least one scheduled task type could supply a crafted property value that caused the system to overwrite the configuration of an unrelated, existing task instead of creating a new one. | |
| Title | Nexus Repository 3 - Improper Input Validation in Scheduled Task Configuration | |
| First Time appeared |
Sonatype
Sonatype nexus Repository Manager |
|
| Weaknesses | CWE-915 | |
| CPEs | cpe:2.3:a:sonatype:nexus_repository_manager:3.91.0:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.91.1:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.92.0:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.92.1:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.92.2:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.92.3:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.93.0:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.93.1:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.93.2:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.94.0:*:*:*:*:*:*:* cpe:2.3:a:sonatype:nexus_repository_manager:3.94.1:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sonatype
Sonatype nexus Repository Manager |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Sonatype
Published:
Updated: 2026-08-07T16:07:42.720Z
Reserved: 2026-07-27T16:30:29.459Z
Link: CVE-2026-17598
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes