Executive brief
MantisBT is a popular open-source bug tracking system. A vulnerability has been identified where low-privileged users can bypass security restrictions to create global profiles, a task normally reserved for administrators. This could allow unauthorized users to modify system-wide settings, potentially impacting the organization's workflow and data integrity.
Technical details
An authorization bypass vulnerability exists in MantisBT due to insufficient validation of the 'user_id' parameter during profile creation. An authenticated attacker with 'add_profile_threshold' permissions can manipulate the 'user_id' parameter in a valid request to create a global profile, even if they lack the 'manage_global_profile_threshold' privilege. This is classified as an Authorization Bypass Through User-Controlled Key (CWE-639). The issue is fixed in version 2.28.2.
Affected products
- MantisBT MantisBT >= 2.28.0, < 2.28.2
Timeline
- 2026-05-09: disclosed: Initial disclosure by researcher
- 2026-05-11: advisory: GitHub Advisory published
- 2026-05-19: patched: NVD publication and patch confirmation