CVE-2026-14645 | Security Details | Sonatype Guide

CVE-2026-14645

Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.

Published Jul 6, 2026

CVSS Score Medium 5.1

Security Details

Components Impacted

Sonatype Research

CVE-2026-14645 Security Details

CVE ID CVE-2026-14645
CWE CWE-918 Learn more about CWE-918

CVE Description Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is granted by role assignment, independent of authentication status, so an unauthenticated user could also trigger this behavior if the anonymous role has been granted the permission.

Published Jul 6, 2026

CVSS Score & Severity 5.1 Medium

CVSS Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N

EPSS Score 0.397%

Malware malware

KEV Status Not in KEV Catalog: No known exploits

Vulnerable Methods

org/sonatype/nexus/internal/webhooks/WebhookServiceImpl.send(Lorg/sonatype/nexus/webhooks/WebhookRequest;)V

JVM Vulnerable params: 0

Affected Ecosystems

Source National Vulnerability Database

References support.sonatype.com