PT-2026-94073 · Manticoresoftware+1 · Manticore Search

·

CVE-2026-92796

·

Published

2026-09-16

·

Updated

2026-09-21

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Manticore Search versions 27.0.0 through 28.4.3
Description Insufficient permission validation for all statements within multi-statement SQL requests allows read-only users to execute unauthorized queries. An attacker can append additional SELECT statements following the initial request to access credential tables and retrieve password hashes, enabling authentication as an administrator without needing the plaintext password.
Recommendations Update Manticore Search to version 28.4.4 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92796

Affected Products

Manticore Search