Vulnerability Description
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sonatype | Nexus Repository Manager | >= 3.0.0, < 3.93.0 |
Related Weaknesses (CWE)
References
- https://help.sonatype.com/en/sonatype-nexus-repository-3-93-0-release-notes.htmlRelease Notes
- https://support.sonatype.com/hc/en-us/articles/52482870409491Vendor Advisory
FAQ
What is CVE-2026-3329?
CVE-2026-3329 is a vulnerability with a CVSS score of 7.5 (HIGH). A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
How severe is CVE-2026-3329?
CVE-2026-3329 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-3329?
Check the references section above for vendor advisories and patch information. Affected products include: Sonatype Nexus Repository Manager.