PT-2026-94073 · Manticoresoftware+1 · Manticore Search
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Manticore Search versions 27.0.0 through 28.4.3
Description
Insufficient permission validation for all statements within multi-statement SQL requests allows read-only users to execute unauthorized queries. An attacker can append additional SELECT statements following the initial request to access credential tables and retrieve password hashes, enabling authentication as an administrator without needing the plaintext password.
Recommendations
Update Manticore Search to version 28.4.4 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Manticore Search