Home

Description

A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.

PUBLISHED Reserved 2026-02-27 | Published 2026-06-11 | Updated 2026-06-11 | Assigner Sonatype




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-307 Improper Restriction of Excessive Authentication Attempts

Product status

Default status
unaffected

3.0.0 (semver) before 3.93.0
affected

Credits

Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. finder

References

help.sonatype.com/...us-repository-3-93-0-release-notes.html patch

support.sonatype.com/hc/en-us/articles/52482870409491 vendor-advisory

cve.org (CVE-2026-3329)

nvd.nist.gov (CVE-2026-3329)

Download JSON