{"id":"CVE-2026-49280","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-49280","summary":"MantisBT: REST API unauthorized Issue status change","details":"A MantisBT user having *$g_update_bug_threshold* (UPDATER by default) can change an Issue's Status via REST and SOAP API, even if the *$g_set_status_threshold* config is set to a higher level (DEVELOPER by default).\n\n### Impact\nUnauthorized change in Issue workflow.\n\n### Patches\nhttps://github.com/mantisbt/mantisbt/releases/tag/release-2.28.4\n\n### Workarounds\nNone\n\n### Resources\n- https://mantisbt.org/bugs/view.php?id=37181\n\n### Credits\nMamdouh Mahfouz (@mamdouhmahfouz)","published":"2026-07-15T17:02:12Z","modified":"2026-07-15T17:26:45.365099Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"2.28.4"}],"fix":{"url":"https://github.com/mantisbt/mantisbt/commit/2d3a5537605487a1ec5178aba9fe9b5623b6a4e0","label":"mantisbt/mantisbt@2d3a553"},"references":[{"type":"WEB","url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-m7ph-9558-mrx3"},{"type":"WEB","url":"https://github.com/mantisbt/mantisbt/commit/2d3a5537605487a1ec5178aba9fe9b5623b6a4e0"},{"type":"PACKAGE","url":"https://github.com/mantisbt/mantisbt"},{"type":"WEB","url":"https://mantisbt.org/bugs/view.php?id=37181"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T17:26:45.365099Z"}}