CVE-2026-7494
Sonatype Nexus 3 vulnerability analysis and mitigation

Overview

CVE-2026-7494 is a Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3, specifically in the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission can cause the server to initiate outbound connections to internal or otherwise restricted network hosts, enabling internal network enumeration and TLS certificate metadata retrieval. The vulnerability affects Nexus Repository 3 CE/Pro versions 3.0.0 through 3.93.x and is fixed in version 3.94.0. It carries a CVSS v4.0 base score of 5.3 (Medium) (Sonatype Advisory, Feedly).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), where the SSL Certificate Retrieval feature fails to validate user-supplied hostnames against internal or private network ranges before establishing outbound connections. An authenticated attacker with the nexus:ssl-truststore:read permission can supply an arbitrary host and port to the endpoint, causing the Nexus Repository server to act as a network proxy and connect to otherwise unreachable internal services. The fix in version 3.94.0 introduces validation of certificate retrieval destinations against internal/private network ranges prior to connection establishment (Sonatype Advisory).

Impact

Successful exploitation allows an attacker to use the Nexus Repository server as a network pivot to probe internal hosts and ports that are not directly accessible to the attacker. Additionally, the attacker can retrieve TLS certificate metadata — including hostnames, organizational details, and fingerprints — from internal services. While direct data exfiltration or code execution is not enabled by this vulnerability, it can facilitate reconnaissance of internal network topology and service discovery, potentially supporting further lateral movement (Sonatype Advisory).

Exploitability

Sonatype has stated it is not aware of any active exploitation of this vulnerability at the time of disclosure. The vulnerability requires authentication and a specific permission (nexus:ssl-truststore:read), limiting the attack surface to users who have been granted this role. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.146%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Sonatype Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a Nexus Repository 3 instance running a version between 3.0.0 and 3.93.x that is accessible over the network.
  2. Obtain credentials: Acquire credentials for a user account that holds the nexus:ssl-truststore:read permission — this may be a low-privileged user with this specific role assigned.
  3. Authenticate: Log in to the Nexus Repository instance using the obtained credentials.
  4. Craft SSRF request: Send a crafted request to the SSL Certificate Retrieval endpoint, supplying an internal or restricted host/port (e.g., 192.168.1.1:22, 10.0.0.1:8080) as the target for certificate retrieval.
  5. Enumerate internal services: Analyze server responses (connection success, timeout, TLS certificate metadata returned) to map internal network hosts, open ports, and service details.
  6. Leverage findings: Use discovered internal hostnames, IP ranges, and service fingerprints to plan further attacks against internal infrastructure (Sonatype Advisory).

Indicators of compromise

  • Network: Unusual outbound connections from the Nexus Repository server to internal RFC-1918 address ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or other restricted hosts on non-standard ports.
  • Logs: Nexus Repository access logs showing repeated requests to the SSL Certificate Retrieval API endpoint with varying internal hostnames or IP addresses as parameters, particularly from a single user account.
  • Logs: Error or timeout log entries in Nexus application logs corresponding to failed connection attempts to internal hosts initiated by the SSL certificate feature.
  • Behavior: A single user account with nexus:ssl-truststore:read permission making an unusually high volume of certificate retrieval requests in a short time window, suggesting automated scanning of internal hosts.

Mitigation and workarounds

Upgrade to Sonatype Nexus Repository CE/Pro version 3.94.0 or later, which validates certificate retrieval destinations against internal/private network ranges before establishing a connection. For administrators who cannot upgrade immediately, Sonatype recommends restricting the nexus:ssl-truststore:read permission to trusted administrative users only, minimizing the number of accounts capable of triggering outbound connections through this feature. This vulnerability was disclosed on July 14, 2026, and the fix was included in the 3.94.0 release (Sonatype Advisory, Sonatype Release Notes).

Community reactions

Sonatype disclosed this vulnerability responsibly on July 14, 2026, crediting the discovery to security researcher Muhamad Burhanudin via Sonatype's Bug Bounty Program. The advisory was published alongside several other Nexus Repository 3 CVEs disclosed on the same date, suggesting a coordinated security release cycle. No significant independent researcher commentary or broad media coverage has been identified beyond the official advisory (Sonatype Advisory).

Additional resources


SourceThis report was generated using AI

Related Sonatype Nexus 3 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-17601HIGH8.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17603HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17600HIGH8.7
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17599MEDIUM6.9
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026
CVE-2026-17598MEDIUM5.3
  • Sonatype Nexus 3 logoSonatype Nexus 3
  • cpe:2.3:a:sonatype:nexus_repository_manager
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management