SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-14646

MEDIUM · CVSS 4.9 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Nexus Repository 3 is vulnerable due to inadequate Server-Side Request Forgery (SSRF) protections for HTTP redirect targets from proxy repository upstream servers. This flaw allows any user with read access to a compromised upstream server to potentially access sensitive internal network information or cloud metadata, including IAM credentials. Organizations using Nexus Repository 3, especially those with anonymous access enabled, should prioritize addressing this vulnerability to safeguard their sensitive data.

CVE
CVE-2026-14646
Severity
MEDIUM
CVSS
4.9
EPSS
0.27%

Original NVD Description

Nexus Repository 3 did not apply its existing Server-Side Request Forgery (SSRF) protections to HTTP redirect targets returned by proxy repository upstream servers. Any user with read access to a proxy repository backed by an attacker-controlled or compromised upstream server — including an anonymous user, if anonymous access is enabled — could receive a response from an internal network address or cloud metadata endpoint as repository content, potentially exposing sensitive information such as cloud IAM credentials.