CVE-2026-3329: Nexus Repository Manager - Improper Restriction of Excessive Authentication Attempts
Published Jun 11, 2026
·Updated
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
Affected Software
2 affected components
Sonatype Nexus Repository Manager
Sonatype Nexus Repository Manager>=3.0.0<3.93.0
Event History
Jun 11, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-3329?
CVE-2026-3329 has a high severity rating of 8.7 according to the CVSS 4.0 score.
2
How do I fix CVE-2026-3329?
To fix CVE-2026-3329, apply the latest patches and updates provided by Sonatype for Nexus Repository Manager.
3
What type of attack does CVE-2026-3329 allow?
CVE-2026-3329 allows remote unauthenticated attackers to conduct credential-guessing attacks against user accounts.
4
Which software is affected by CVE-2026-3329?
CVE-2026-3329 affects Sonatype Nexus Repository Manager.
5
When was CVE-2026-3329 published?
CVE-2026-3329 was published on June 11, 2026.