A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
References
| Link | Resource |
|---|---|
| https://help.sonatype.com/en/sonatype-nexus-repository-3-93-0-release-notes.html | Release Notes |
| https://support.sonatype.com/hc/en-us/articles/52482870409491 | Vendor Advisory |
Configurations
History
21 Jul 2026, 15:21
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://help.sonatype.com/en/sonatype-nexus-repository-3-93-0-release-notes.html - Release Notes | |
| References | () https://support.sonatype.com/hc/en-us/articles/52482870409491 - Vendor Advisory | |
| CPE | cpe:2.3:a:sonatype:nexus_repository_manager:*:*:*:*:*:*:*:* | |
| First Time |
Sonatype nexus Repository Manager
Sonatype |
11 Jun 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-11 18:16
Updated : 2026-07-21 15:21
NVD link : CVE-2026-3329
Mitre link : CVE-2026-3329
CVE.ORG link : CVE-2026-3329
JSON object : View
Products Affected
sonatype
- nexus_repository_manager
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts
