{"id":"CVE-2026-52882","aliases":["GHSA-3v2j-6fw9-f57c"],"title":"MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters","summary":"MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters","severity":"medium","cwe":["CWE-639"],"vendor":"mantisbt","product":"mantisbt/mantisbt","ecosystem":"composer","affected":["mantisbt/mantisbt <= 2.28.3"],"patched":["mantisbt/mantisbt 2.28.4"],"published":"2026-07-15","updated":"2026-07-15","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-3v2j-6fw9-f57c","references":[{"url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-3v2j-6fw9-f57c"},{"url":"https://github.com/mantisbt/mantisbt/commit/17072d4c322c85f7135ebec3417a6d90b525d12f"},{"url":"https://mantisbt.org/bugs/view.php?id=37065"},{"url":"https://github.com/advisories/GHSA-3v2j-6fw9-f57c"}],"tags":["ghsa","composer"],"ingestedAt":"2026-07-15T18:45:16.832Z","slug":"CVE-2026-52882","body":"## Overview\n\n### Impact\nUsers below _report_issues_for_unreleased_versions_threshold_ can assign unreleased product versions.\n\n### Patches\n- https://github.com/mantisbt/mantisbt/commit/17072d4c322c85f7135ebec3417a6d90b525d12f\n\n### Workarounds\nNone\n\n### Resources\n- https://mantisbt.org/bugs/view.php?id=37065\n\n### Credits\nMantisBT thanks Vishal Shukla for discovering and responsibly reporting the issue.\n\n## Affected packages\n\n- `mantisbt/mantisbt <= 2.28.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `mantisbt/mantisbt 2.28.4`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}