{"id":"CVE-2026-49280","aliases":["GHSA-m7ph-9558-mrx3"],"title":"MantisBT: REST API unauthorized Issue status change","summary":"MantisBT: REST API unauthorized Issue status change","severity":"medium","cwe":["CWE-862"],"vendor":"mantisbt","product":"mantisbt/mantisbt","ecosystem":"composer","affected":["mantisbt/mantisbt >= 2.8.0, <= 2.28.3"],"patched":["mantisbt/mantisbt 2.28.4"],"published":"2026-07-15","updated":"2026-07-15","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-m7ph-9558-mrx3","references":[{"url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-m7ph-9558-mrx3"},{"url":"https://github.com/mantisbt/mantisbt/commit/2d3a5537605487a1ec5178aba9fe9b5623b6a4e0"},{"url":"https://mantisbt.org/bugs/view.php?id=37181"},{"url":"https://github.com/advisories/GHSA-m7ph-9558-mrx3"}],"tags":["ghsa","composer"],"ingestedAt":"2026-07-15T17:44:34.608Z","slug":"CVE-2026-49280","body":"## Overview\n\nA MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default).\n\n### Impact\nUnauthorized change in Issue workflow.\n\n### Patches\nhttps://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4\n\n### Workarounds\nNone\n\n### Resources\n- https://mantisbt.org/bugs/view.php?id=37181\n\n### Credits\nMamdouh Mahfouz (@mamdouhmahfouz)\n\n## Affected packages\n\n- `mantisbt/mantisbt >= 2.8.0, <= 2.28.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `mantisbt/mantisbt 2.28.4`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}