Junglewise Threat Intelligence

CVE-2026-3329: Sonatype Nexus Repository improper restriction of authentication attempts

CVE-2026-3329 · Severity: info · CVSS 8.7 · Published 2026-06-11

Technologies: Sonatype Nexus Repository. Vendors: Sonatype.

Executive brief

Sonatype Nexus Repository, a platform used by organizations to manage and store software components, is vulnerable to credential-guessing attacks. An unauthorized attacker could repeatedly attempt to guess user passwords through the system's login interfaces without being blocked. If successful, this could lead to unauthorized access to sensitive software code, proprietary packages, and internal development resources.

Technical details

Sonatype Nexus Repository is vulnerable to improper restriction of excessive authentication attempts (CWE-307) within its authentication endpoints. A remote, unauthenticated attacker can launch brute-force or dictionary attacks to guess user credentials because the system fails to adequately throttle or block repeated failed login attempts. Successful exploitation allows an attacker to gain unauthorized access to user accounts, potentially leading to the compromise of hosted repositories and administrative functions. The vulnerability is addressed in Sonatype Nexus Repository version 3.93.0.

Affected products

  • Sonatype Nexus Repository Fixed in 3.93.0

Timeline

  • 2026-06-11: disclosed
  • 2026-06-11: advisory

References

Related threats