Impact
The vulnerability exposes a password‑change endpoint that does not confirm an ongoing onboarding process before changing the administrator account password, and it does not trigger a session invalidation after the change. When a user with the nexus:* permission invokes the endpoint, they can replace the admin password and keep any existing sessions active. This can lead to loss of control over the repository, as the original administrator can simultaneously lock themselves out or maintain unauthorized access.
Affected Systems
The flaw is present in Sonatype Nexus Repository 3 releases from 3.17.0 up through 3.94.1, inclusive. All instances running any of these versions are susceptible unless upgraded.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity and the lack of an EPSS score suggests limited published exploitation evidence. The vulnerability requires the attacker to be authenticated with at least nexus:* rights, which typically signifies high privileged or compromised credentials, and the attack vector is remote via an HTTP request to the exposed endpoint. The risk is amplified by the fact that session invalidation does not occur, allowing the attacker to maintain access. Because the issue is not listed in KEV, there is no publicly known exploitation but the potential impact warrants immediate mitigation.
OpenCVE Enrichment