CVE-2026-14645

MEDIUM

Nexus Repository 3 - Server-Side Request Forgery (SSRF) via Webhook: Global Capability

Title source: cna
STIX 2.1

Description

Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.

Scores

CVSS v4 5.1
EPSS 0.0040
EPSS Percentile 32.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (1)
Sonatype/Nexus Repository 3 3.0.0 - 3.94.0
Published Jul 14, 2026
Tracked Since Jul 14, 2026