PT-2026-27178 · Unknown+1 · Mantis Bug Tracker+1
Jbince
·
Published
2026-03-23
·
Updated
2026-03-27
·
CVE-2026-30849
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mantis Bug Tracker versions prior to 2.28.1
Description
Mantis Bug Tracker is an open source issue tracker. Instances running on MySQL family databases are affected by an authentication bypass in the SOAP API due to improper type checking on the
password parameter. An attacker knowing a victim's username can log in to the SOAP API without the actual password and execute any API function they have access to by using a crafted SOAP envelope. The issue stems from MySQL's implicit string-to-integer conversion during password checks. Disabling the SOAP API reduces the risk, but an attacker can still retrieve user account information, including email address and real name.Recommendations
Versions prior to 2.28.1 should be updated to version 2.28.1 or later.
As a workaround, disable the SOAP API.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mantis Bug Tracker
Mysql Server