CVE-2026-3329
Received
Received - Intake
Unauthenticated Credential Guessing in Sonatype Nexus Repository
Publication date: 2026-06-11
Last updated on: 2026-06-11
Assigner: Sonatype
Description
Description
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sonatype | nexus_repository | From 3.0.0 (inc) to 3.92.x (inc) |
| sonatype | nexus_repository | 3.93.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-307 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame. |