CVE-2026-14645: Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capabi
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-14645
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-146450.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 32% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-14645 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for Nexus Repository
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[NEW] [medium] Sonatype Nexus Repository Manager: Multiple vulnerabilitiescert-bund · 2026-07-15
- unknownCVE-2026-14646: Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections t…nvd · 2026-07-14
- unknownCVE-2026-7494: Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate …nvd · 2026-07-14
- unknownCVE-2026-14504: An authorization bypass in Nexus Repository 3's component upload API allowed a user with only …nvd · 2026-07-14
- unknownCVE-2026-11403: A vulnerability in Sonatype Nexus Repository Manager's format-specific API key generation may …nvd · 2026-07-14
- criticalexploitedCVE-2019-7238: Sonatype Nexus Repository Manager Incorrect Access Control Vulnerabilitycisa-kev · 2021-12-10
More from NVD Recent CVEs
- highCVE-2026-10848: The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (…2026-08-02
- highCVE-2026-9856: A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform…2026-08-02
- criticalCVE-2026-65321: PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated at…2026-08-02
- lowCVE-2026-10774: Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-ke…2026-08-02
- mediumCVE-2026-68583: luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in t…2026-08-02