github.com
https://github.com/mantisbt/mantisbt CVE-2026-49280
MantisBT: REST API unauthorized Issue status change
Description
A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default). ### Impact Unauthorized change in Issue workflow. ### Patches https://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4 ### Workarounds None ### Resources - https://mantisbt.org/bugs/view.php?id=37181 ### Credits Mamdouh Mahfouz (@mamdouhmahfouz)
Description source: GitHub Advisory
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
mantisbt/mantisbtBrowse Packagist / mantisbt/mantisbt | GitHub Advisory | 2.8.0 to < 2.28.4 · Fixed in 2.28.4 | affected |
References
4github.com
https://github.com/mantisbt/mantisbt/commit/2d3a5537605487a1ec5178aba9fe9b5623b6a4e0 github.com
https://github.com/mantisbt/mantisbt/security/advisories/GHSA-m7ph-9558-mrx3 mantisbt.org
https://mantisbt.org/bugs/view.php?id=37181