216.73.216.197

CVE-2026-3048

· Published 11/05/2026 18:16 · Modified 11/05/2026 18:16

Labels: CVE-2026-3048 103e4ec9-0a87-450b-af77-479448ddef112026-05-11CVE-2026-3048CWE-502

Essential information

Published
11/05/2026 18:16
Modified
11/05/2026 18:16
Author
Creator
CVSS
5.1 MEDIUM (v3) 5.1 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections when interacting with a malicious LDAP server.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
103e4ec9-0a87-450b-af77-479448ddef11
NVD
View on NVD

Affected products (CPE)

ProductCPE
sonatype / nexus repository manager cpe:2.3:a:sonatype:nexus_repository_manager:3.0.0-3.91.1:*:*:*:*:*:*:*

References