
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-7494 is a Server-Side Request Forgery (SSRF) vulnerability in Sonatype Nexus Repository 3, specifically in the SSL Certificate Retrieval endpoint. A user holding the nexus:ssl-truststore:read permission can cause the server to initiate outbound connections to internal or otherwise restricted network hosts, enabling internal network enumeration and TLS certificate metadata retrieval. The vulnerability affects Nexus Repository 3 CE/Pro versions 3.0.0 through 3.93.x and is fixed in version 3.94.0. It carries a CVSS v4.0 base score of 5.3 (Medium) (Sonatype Advisory, Feedly).
The root cause is classified as CWE-918 (Server-Side Request Forgery), where the SSL Certificate Retrieval feature fails to validate user-supplied hostnames against internal or private network ranges before establishing outbound connections. An authenticated attacker with the nexus:ssl-truststore:read permission can supply an arbitrary host and port to the endpoint, causing the Nexus Repository server to act as a network proxy and connect to otherwise unreachable internal services. The fix in version 3.94.0 introduces validation of certificate retrieval destinations against internal/private network ranges prior to connection establishment (Sonatype Advisory).
Successful exploitation allows an attacker to use the Nexus Repository server as a network pivot to probe internal hosts and ports that are not directly accessible to the attacker. Additionally, the attacker can retrieve TLS certificate metadata — including hostnames, organizational details, and fingerprints — from internal services. While direct data exfiltration or code execution is not enabled by this vulnerability, it can facilitate reconnaissance of internal network topology and service discovery, potentially supporting further lateral movement (Sonatype Advisory).
Sonatype has stated it is not aware of any active exploitation of this vulnerability at the time of disclosure. The vulnerability requires authentication and a specific permission (nexus:ssl-truststore:read), limiting the attack surface to users who have been granted this role. No public proof-of-concept exploit code has been identified. The EPSS score is approximately 0.146%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Sonatype Advisory, Feedly).
nexus:ssl-truststore:read permission — this may be a low-privileged user with this specific role assigned.192.168.1.1:22, 10.0.0.1:8080) as the target for certificate retrieval.nexus:ssl-truststore:read permission making an unusually high volume of certificate retrieval requests in a short time window, suggesting automated scanning of internal hosts.Upgrade to Sonatype Nexus Repository CE/Pro version 3.94.0 or later, which validates certificate retrieval destinations against internal/private network ranges before establishing a connection. For administrators who cannot upgrade immediately, Sonatype recommends restricting the nexus:ssl-truststore:read permission to trusted administrative users only, minimizing the number of accounts capable of triggering outbound connections through this feature. This vulnerability was disclosed on July 14, 2026, and the fix was included in the 3.94.0 release (Sonatype Advisory, Sonatype Release Notes).
Sonatype disclosed this vulnerability responsibly on July 14, 2026, crediting the discovery to security researcher Muhamad Burhanudin via Sonatype's Bug Bounty Program. The advisory was published alongside several other Nexus Repository 3 CVEs disclosed on the same date, suggesting a coordinated security release cycle. No significant independent researcher commentary or broad media coverage has been identified beyond the official advisory (Sonatype Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."