CVE-2026-14645

Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.
CVSS

No CVSS.

Configurations

No configuration.

History

14 Jul 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 17:16

Updated : 2026-07-15 20:08


NVD link : CVE-2026-14645

Mitre link : CVE-2026-14645

CVE.ORG link : CVE-2026-14645


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)