SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-7494

MEDIUM · CVSS 5.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

Nexus Repository 3 is susceptible to Server-Side Request Forgery (SSRF) through its SSL Certificate Retrieval endpoint, allowing users with the nexus:ssl-truststore:read permission to trigger outbound connections to internal or restricted network hosts. This vulnerability could lead to unauthorized access to sensitive internal resources. Organizations using affected versions of Nexus Repository, particularly those with sensitive internal networks, should prioritize remediation to mitigate potential security risks.

CVE
CVE-2026-7494
Severity
MEDIUM
CVSS
5.3
EPSS
0.15%

Original NVD Description

Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.