Executive brief
MantisBT is a popular open-source bug tracking system. A vulnerability in its API allows users with low-level permissions to assign unreleased product versions to issues, bypassing intended administrative restrictions. This could lead to data inconsistency or the unauthorized disclosure of upcoming product version names within the tracking system.
Technical details
An authorization bypass vulnerability (CWE-639) exists in the REST and SOAP APIs of MantisBT. The issue update logic fails to properly enforce the '_report_issues_for_unreleased_versions_threshold_' configuration when processing requests through these APIs. An authenticated attacker with low privileges can exploit this to assign unreleased product versions to bug reports, a task normally restricted to higher-privileged users. This issue is fixed in version 2.28.4.
Affected products
- MantisBT MantisBT <= 2.28.3
Timeline
- 2026-07-15: disclosed
- 2026-07-15: patched