CVE-2026-3329 Details
Description
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
A vulnerability exists in Sonatype Nexus Repository versions 3.0.0 prior to 3.93.0, allowing remote unauthenticated attackers to perform credential-guessing attacks against user accounts via authentication endpoints. Exploitation of this vulnerability could lead to unauthorized access to the repository, with potential exposure of sensitive artifacts and configuration data.
Users are advised to upgrade to Sonatype Nexus Repository version 3.93.0 or later. For those unable to upgrade immediately, it is recommended to restrict network access to trusted IP ranges, deploy a reverse proxy or Web Application Firewall with authentication rate limiting, enable Single Sign-On for UI authentication, and monitor authentication logs for unusual failed login patterns.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://help.sonatype.com/en/sonatype-nexus-repository-3-93-0-release-notes.html | Sonatype | Release Notes |
| https://support.sonatype.com/hc/en-us/articles/52482870409491 | Sonatype | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-307 | Improper Restriction of Excessive Authentication Attempts | Sonatype |
Affected Products
| Product | Versions |
|---|---|
| sonatype nexus repository manager | >= 3.0.0, < 3.93.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 21, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | Sonatype |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | New CVE Received | Sonatype |