PT-2026-39873 · Mantisbt · Mantisbt

Published

2026-05-11

·

Updated

2026-05-19

·

CVE-2026-33052

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mantis Bug Tracker (MantisBT) versions 2.28.0 through 2.28.1
Description A low-privileged authenticated user with the add profile threshold permission can create a global profile even without the manage global profile threshold permission. This is achieved by tampering with the user id parameter during a valid profile creation request, leading to privilege escalation.
Recommendations Update to version 2.28.2.

Exploit

Fix

LPE

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-33052
GHSA-68W5-W573-Q2R8

Affected Products

Mantisbt