VYPR
Medium severityNVD Advisory· Published Jul 15, 2026

MantisBT: REST API unauthorized Issue status change

CVE-2026-49280

Description

A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default).

Impact

Unauthorized change in Issue workflow.

### Patches https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4

Workarounds

None

### Resources - https://mantisbt.org/bugs/view.php?id=37181

Credits

Mamdouh Mahfouz (@mamdouhmahfouz)

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mantisbt/mantisbtPackagist
>= 2.8.0, < 2.28.42.28.4

Affected products

1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.