CVE-2026-14645
MEDIUMNexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global Capability
Title source: cnaDescription
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://support.sonatype.com/hc/en-us/articles/53158843564179/
Scores
CVSS v4
5.1
EPSS
0.0040
EPSS Percentile
32.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-918
Status
published
Products (1)
Sonatype/Nexus Repository 3
3.0.0 - 3.94.0
Published
Jul 14, 2026
Tracked Since
Jul 14, 2026