Nexus Repository 3: HikariCP Connection Property RCE via DataStore API
CVE-2026-17603 Published on August 7, 2026

Nexus Repository 3 - HikariCP connectionInitSql Injection RCE via DataStore Configuration API
Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the configured database on every new connection. On the default H2 database backend, this could be leveraged to achieve remote code execution as the Nexus process user.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-17603 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
NONE

Weakness Type

What is a Code Injection Vulnerability?

The software constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

CVE-2026-17603 has been classified to as a Code Injection vulnerability or weakness.


Products Associated with CVE-2026-17603

Want to know whenever a new CVE is published for Sonatype Nexus Repository Manager? stack.watch will email you.

 

Affected Versions

Sonatype Nexus Repository 3: