CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-3v2j-6fw9-f57c: MantisBT: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters

mediumCVE-2026-52882
Impact Users below _report_issues_for_unreleased_versions_threshold_ can assign unreleased product versions. Patches - https://github.com/mantisbt/mantisbt/commit/17072d4c322c85f7135ebec3417a6d90b525d12f Workarounds None Resources - https://mantisbt.org/bugs/view.php?id=37065 Credits MantisBT thanks Vishal Shukla for discovering and responsibly reporting the issue.

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
medium
Published
2026-07-15
Last updated
2026-07-15
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-3v2j-6fw9-f57c

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-52882coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories