Medium severityNVD Advisory· Published Jul 15, 2026
MantisBT: REST API unauthorized Issue status change
CVE-2026-49280
Description
A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default).
Impact
Unauthorized change in Issue workflow.
### Patches https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4
Workarounds
None
### Resources - https://mantisbt.org/bugs/view.php?id=37181
Credits
Mamdouh Mahfouz (@mamdouhmahfouz)
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mantisbt/mantisbtPackagist | >= 2.8.0, < 2.28.4 | 2.28.4 |
Affected products
1Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.