THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-17595 — Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JV

[NVD] CVE-2026-17595 — Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JV

mednvdPublished 2026-08-07

CVE-2026-17595 CVSS: None Published: 2026-08-07T17:16:59.760

Nexus Repository 3 did not fully sandbox JEXL expressions used in Content Selectors. An account holding the nexus:selectors:create permission could construct an expression that read Java object properties not intended to be exposed to the expression engine, disclosing internal JVM class metadata such as class and classloader names. Thi

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-17595