<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:26:06 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-349424</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-349424</link>
      <description>EUVD-2026-349424</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-349424</guid>
    </item>
    <item>
      <title>fkie_cve-2026-17599</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-17599</link>
      <description>&lt;p&gt;Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-17599</guid>
    </item>
    <item>
      <title>GHSA-jffj-qrgg-8qm5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jffj-qrgg-8qm5</link>
      <description>&lt;p&gt;Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Nexus Repository 3 contained an endpoint used to change the administrator account password during initial onboarding. This endpoint did not verify that onboarding was still in progress before allowing the password change, relying instead on the presence of a local onboarding artifact. As a result, an account holding the nexus:* permission could invoke the endpoint outside the intended onboarding flow to replace the administrator password, and existing sessions were not invalidated after the change.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jffj-qrgg-8qm5</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2713 — Sonatype Nexus Repository Manager: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2713</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Sonatype Nexus Repository Manager ausnutzen, um Daten offenzulegen oder zu Manipulieren, Code auszuführen oder Rechte zu erweitern.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Sonatype Nexus Repository Manager ausnutzen, um Daten offenzulegen oder zu Manipulieren, Code auszuführen oder Rechte zu erweitern.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2713</guid>
    </item>
  </channel>
</rss>
