CVE-2026-3048: Nexus Repository 3 - Improper LDAP Referral Handling
An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3048?
CVE-2026-3048 is considered a medium severity vulnerability due to its potential for server-side connections to malicious LDAP servers.
How do I fix CVE-2026-3048?
To fix CVE-2026-3048, upgrade to Sonatype Nexus Repository Manager version 3.92.0 or later.
Who is affected by CVE-2026-3048?
CVE-2026-3048 affects authenticated administrators using Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1.
What type of vulnerability is CVE-2026-3048?
CVE-2026-3048 is classified as an improper handling of LDAP referrals vulnerability.
What can attackers do with CVE-2026-3048?
Attackers can potentially initiate unintended server-side connections by exploiting improper LDAP referral handling in the affected software.