Feed/CVE-2026-49280
CVE-2026-49280MEDIUMCVSS 0.0

MantisBT: REST API unauthorized Issue status change

Published Jul 15, 2026·Updated Jul 15, 2026

NVD Description

A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default). ### Impact Unauthorized change in Issue workflow. ### Patches https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4 ### Workarounds None ### Resources - https://mantisbt.org/bugs/view.php?id=37181 ### Credits Mamdouh Mahfouz (@mamdouhmahfouz)

Affected Packages (1)

mantisbt/mantisbtCOMPOSER
From 2.8.0
Fixed in = 2.28.3

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free