CVE-2026-7494 Details
Description
Nexus Repository 3 is vulnerable to Server-Side Request Forgery (SSRF) via the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission could cause the server to initiate outbound connections to internal or otherwise restricted network hosts. This issue affects Nexus Repository 3.0.0 through versions prior to 3.94.0.
A Server-Side Request Forgery (SSRF) vulnerability exists in Sonatype Nexus Repository 3, specifically in versions 3.0.0 through 3.93.x. The vulnerability arises in the SSL Certificate Retrieval endpoint, where a user with the 'nexus:ssl-truststore:read' permission can manipulate the server into making outbound connections to internal or restricted network hosts. This could potentially be exploited to probe internal services and retrieve TLS certificate information from them.
Users are advised to upgrade to Sonatype Nexus Repository 3.94.0 or later, which includes fixes for this vulnerability. For those unable to upgrade immediately, it is recommended to restrict the 'nexus:ssl-truststore:read' permission to trusted administrative users only.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.sonatype.com/en/sonatype-nexus-repository-3-94-0-release-notes.html | Sonatype | Release Notes |
| https://support.sonatype.com/hc/en-us/articles/53126069518227 | Sonatype | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | Sonatype |
Affected Products
| Product | Versions |
|---|---|
| sonatype nexus repository manager | >= 3.0.0, < 3.94.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | Reanalysis | [email protected] |
| Sep 22, 2026 | Initial Analysis | [email protected] |
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | Sonatype |