PT-2026-39873 · Mantisbt · Mantisbt

CVE-2026-33052

·

Published

2026-05-11

·

Updated

2026-05-19

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mantis Bug Tracker (MantisBT) versions 2.28.0 through 2.28.1
Description A low-privileged authenticated user with the add profile threshold permission can create a global profile even without the manage global profile threshold permission. This is achieved by tampering with the user id parameter during a valid profile creation request, leading to privilege escalation.
Recommendations Update to version 2.28.2.

Exploit

Fix

LPE

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33052
GHSA-68W5-W573-Q2R8

Affected Products

Mantisbt