Junglewise Threat Intelligence

CVE-2026-49280: MantisBT unauthorized issue status change in REST and SOAP API

CVE-2026-49280 · Severity: medium · CVSS 4 · Published 2026-07-15

Technologies: mantisbt/mantisbt (Packagist), MantisBT. Vendors: Packagist, MantisBT.

Executive brief

MantisBT is a popular open-source bug tracking system. A vulnerability in its API allows users with low-level 'Updater' permissions to change the status of issues even when the system is configured to require higher 'Developer' permissions for such actions. This could allow unauthorized users to disrupt project workflows or prematurely close bug reports.

Technical details

A missing authorization check (CWE-862) in the MantisBT REST and SOAP APIs allows users with the $g_update_bug_threshold (typically 'Updater') to modify an issue's status. This occurs even if the $g_set_status_threshold configuration is set to a more restrictive level, such as 'Developer'. An authenticated attacker with network access to the API can exploit this to bypass intended workflow restrictions and modify issue metadata. The issue is resolved in version 2.28.4.

Affected products

  • MantisBT MantisBT >= 2.8.0, <= 2.28.3

Timeline

  • 2026-07-15: disclosed
  • 2026-07-15: advisory
  • 2026-07-15: patched

References

Related threats