THREAT OPS › Threat News › [NVD] CVE-2026-14645 (MEDIUM 5.5) — Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (S
[NVD] CVE-2026-14645 (MEDIUM 5.5) — Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (S
CVE-2026-14645 CVSS: 5.5 MEDIUM Published: 2026-07-14T17:16:44.130
Nexus Repository 3 does not validate the destination of the "Webhook: Global" capability's configured URL before making an outbound HTTP request, allowing a user holding the Capability Administration permission to cause the server to send requests to internal network locations (Server-Side Request Forgery). This permission is gran
Indicators of compromise
- CVE-2026-14645cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-14645