{"id":"CVE-2026-52882","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-52882","summary":"MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters","details":"### Impact\nUsers below _report_issues_for_unreleased_versions_threshold_ can assign unreleased product versions.\n\n### Patches\n- https://github.com/mantisbt/mantisbt/commit/17072d4c322c85f7135ebec3417a6d90b525d12f\n\n### Workarounds\nNone\n\n### Resources\n- https://mantisbt.org/bugs/view.php?id=37065\n\n### Credits\nMantisBT thanks Vishal Shukla for discovering and responsibly reporting the issue.","published":"2026-07-15T18:41:55Z","modified":"2026-07-15T19:11:50.290742Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"2.28.4"}],"fix":{"url":"https://github.com/mantisbt/mantisbt/commit/17072d4c322c85f7135ebec3417a6d90b525d12f","label":"mantisbt/mantisbt@17072d4"},"references":[{"type":"WEB","url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-3v2j-6fw9-f57c"},{"type":"WEB","url":"https://github.com/mantisbt/mantisbt/commit/17072d4c322c85f7135ebec3417a6d90b525d12f"},{"type":"PACKAGE","url":"https://github.com/mantisbt/mantisbt"},{"type":"WEB","url":"https://mantisbt.org/bugs/view.php?id=37065"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T19:11:50.290742Z"}}