Junglewise Threat Intelligence

CVE-2026-33052: MantisBT authorization bypass in global profile creation

CVE-2026-33052 · Severity: medium · CVSS 4 · Published 2026-05-19

Technologies: mantisbt/mantisbt (Packagist), MantisBT. Vendors: Packagist, MantisBT.

Executive brief

MantisBT is a popular open-source bug tracking system. A vulnerability has been identified where low-privileged users can bypass security restrictions to create global profiles, a task normally reserved for administrators. This could allow unauthorized users to modify system-wide settings, potentially impacting the organization's workflow and data integrity.

Technical details

An authorization bypass vulnerability exists in MantisBT due to insufficient validation of the 'user_id' parameter during profile creation. An authenticated attacker with 'add_profile_threshold' permissions can manipulate the 'user_id' parameter in a valid request to create a global profile, even if they lack the 'manage_global_profile_threshold' privilege. This is classified as an Authorization Bypass Through User-Controlled Key (CWE-639). The issue is fixed in version 2.28.2.

Affected products

  • MantisBT MantisBT >= 2.28.0, < 2.28.2

Timeline

  • 2026-05-09: disclosed: Initial disclosure by researcher
  • 2026-05-11: advisory: GitHub Advisory published
  • 2026-05-19: patched: NVD publication and patch confirmation

References

Related threats