Executive brief
MantisBT, a popular open-source bug tracking system, contains a vulnerability that allows project managers to elevate their own or others' privileges to project-level administrator. While this does not grant full system-wide administrative control, it allows unauthorized access to project-specific settings. This could lead to unauthorized configuration changes within specific projects.
Technical details
A privilege escalation vulnerability exists in MantisBT's ProjectUsersAddCommand, affecting both the web UI (manage_proj_user_add.php) and the REST API (PUT /project/{id}/users). While the frontend UI restricts selectable access levels based on the user's role, the backend fails to validate the 'access_level' parameter in the request. An attacker with 'manager' privileges can submit a forged request to assign the 'administrator' role at the project level. This role is limited to project-specific actions and does not grant global instance-wide administrative rights. The issue is fixed in version 2.28.2.
Affected products
- MantisBT MantisBT <= 2.28.1
Timeline
- 2026-05-09: disclosed
- 2026-05-11: advisory: GitHub Advisory published
- 2026-05-19: other: NVD published
References
- https://api.github.com/users/dracosectech-code
- https://github.com/dracosectech-code
- https://api.github.com/users/dracosectech-code/gists%7B/gist_id%7D
- https://api.github.com/users/dracosectech-code/repos
- https://avatars.githubusercontent.com/u/266971538?v=4
- https://api.github.com/users/dracosectech-code/events%7B/privacy%7D