CVE-2026-49280Medium▾ SunlitMantisBT: REST API unauthorized Issue status change
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A MantisBT user having $g_update_bug_threshold (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the $g_set_status_threshold config is set to a higher level (DEVELOPER by default).
Unauthorized change in Issue workflow.
https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4
None
Mamdouh Mahfouz (@mamdouhmahfouz)
mantisbt/mantisbt >= 2.8.0, <= 2.28.3Upgrade to a patched release:
mantisbt/mantisbt 2.28.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-52883MediumMantisBT: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs
CVE-2026-62944HighMantisBT: Stored XSS in print_all_bug_page_word.php
CVE-2026-52847CriticalMantisBT: Reflected XSS in admin/install.php
CVE-2026-52881CriticalMantisBT: Reflected XSS in admin/install.php via unescaped printf
CVE-2026-52882MediumMantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters
CVE-2026-49273HighMantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php