CVE-2026-30849Disclosure(mantisbt / mantisbt)

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch mantisbt mantisbt systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions prior to 2.28.1 running on MySQL family databases are affected by an authentication bypass vulnerability in the SOAP API, as a result of an improper type checking on the password parameter. Other database backends are not affected, as they do not perform implicit type conversion from string to integer. Using a crafted SOAP envelope, an attacker knowing the victim's username is able to login to the SOAP API with their account without knowledge of the actual password, and execute any API function they have access to. Version 2.28.1 contains a patch. Disabling the SOAP API significantly reduces the risk, but still allows the attacker to retrieve user account information including email address and real name.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-305

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mantisbt

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-03-25); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
mantisbt

Deep dive

Activity timeline8 mentions / 6d
01223Mentions · 2026-03-23: 1Mentions · 2026-03-25: 3Mentions · 2026-03-27: 1Mentions · 2026-03-29: 1Mentions · 2026-06-06: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-06-06: 1PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-06-06: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-27: 1Technical Details · 2026-03-29: 1Technical Details · 2026-06-06: 1Technical Details · 2026-09-11: 103-2303-2503-2703-2906-0609-11
Signal classification4 categories
Disclosure
562.5%
General
112.5%
Patch
112.5%
PoC
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-231
Disclosure1
2026-03-253
Disclosure2General1
2026-03-271
Patch1
2026-03-291
Disclosure1
2026-06-061
PoC1
2026-09-111
Disclosure1
Full discourse8 posts
  • .joward@jowardsec
    General

    Very pleased to share a recent CVE of mine, CVE-2026-30849: https://blog.shellntel.com/p/casting-spells-and-data-types-mantis-bug-tracker-cve-2026-30849

    Post summary

    The author announces a CVE (CVE-2026-30849) and links to a blog post, but offers no technical details, exploit code, or evidence of active exploitation.

    1801662.0K
    91 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    MantisBT patches a critical 9.3 CVSS auth bypass (CVE-2026-30849) and high-severity XSS flaws. Learn how MySQL type conversion opens the door. Update now! #MantisBT #CyberSecurity #AuthBypass #InfoSec #Vulnerability #PatchNow #MySQL #SOAP #BugTracker #XSS https://securityonline.info/mantisbt-critical-authentication-bypass-vulnerability-cve-2026-30849/ https://t.co/nIzL4AN3Rw

    Post summary

    The post announces that MantisBT has released a patch for a critical authentication bypass (CVE‑2026‑30849) and associated XSS flaws, urging users to update immediately. It highlights the vulnerability details but provides no PoC or exploit code.

    06092669
    11.0K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-30849 - critical 🚨 MantisBT < 2.28.1 - SOAP API Authentication Bypass > Mantis Bug Tracker < 2.28.1 on MySQL databases contains an authentication bypass caus... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-30849 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces the critical CVE‑2026‑30849 for MantisBT versions below 2.28.1, detailing a SOAP API authentication bypass and linking to a resource that likely provides further information.

    01087600
    1.3K followersView on X
  • Gumbraise.𝚟𝚞𝚎@gumbraise
    PoC

    GitHub - Gumbraise/CVE-2026-30849-PoC: A simple, educational proof-of-concept script demonstrating the exploit for MantisBT SOAP auth bypass (CVE-2026-30849). - https://github.com/Gumbraise/CVE-2026-30849-PoC

    Post summary

    This GitHub repo presents a proof‑of‑concept script that demonstrates an authentication bypass vulnerability (CVE‑2026‑30849) in MantisBT's SOAP interface.

    00000408
    214 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    Critical 9.3 CVSS Auth Bypass and XSS Flaws Hit MantisBT https://securityonline.info/mantisbt-critical-authentication-bypass-vulnerability-cve-2026-30849/

    Post summary

    The announcement reports a high‑severity (CVSS 9.3) authentication bypass and XSS flaw (CVE‑2026‑30849) in MantisBT, but offers no PoC, exploit code, active exploitation evidence, or mitigation details.

    0000043
    244 followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    Critical MantisBT flaw (CVE-2026-30849) enables SOAP API auth bypass via MySQL type casting, allowing attackers to log in as admin using password “0” and gain full project access. #CyberSecurity #Vulnerability #CVE https://blog.shellntel.com/p/casting-spells-and-data-types-mantis-bug-tracker-cve-2026-30849

    Post summary

    The post announces a critical MantisBT vulnerability (CVE‑2026‑30849) that allows SOAP API authentication bypass through MySQL type casting, enabling attackers to log in as admin.

    0000041
    344 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    An authentication bypass vulnerability (CVE-2026-30849) affects `MantisBT` via its SOAP API when using MySQL. Assess `SOAP API` exposure. #MantisBT #AuthBypass #infosec https://www.pulsepatch.io/posts/cve-2026-30849-mantisbt-authentication-bypass-soap-mysql

    Post summary

    The post announces CVE‑2026‑30849, an authentication bypass in MantisBT's SOAP API with MySQL, without providing PoC, exploit code, or patch details.

    0000046
    2 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30849: MantisBT SOAP API has an authent... MySQL's implicit string-to-int conversion turns SOAP password checks into a joke—just craft the right envelope and you'... https://zerodaysignal.com/vulnerability/CVE-2026-30849 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A zero‑day authentication bypass in the MantisBT SOAP API has been disclosed, relying on MySQL string‑to‑int conversion; details are linked but no exploit code or patch is mentioned.

    0000064
    164 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmantisbtmantisbt---

Explore more