Vivek | Cybersecurity[verified]@VivekIntelDisclosure
The post announces a critical MantisBT vulnerability (CVE‑2026‑30849) that allows SOAP API authentication bypass through MySQL type casting, enabling attackers to log in as admin.
.joward@jowardsecGeneral
The author announces a CVE (CVE-2026-30849) and links to a blog post, but offers no technical details, exploit code, or evidence of active exploitation.
Gray Hats@the_yellow_fallPatch
The post announces that MantisBT has released a patch for a critical authentication bypass (CVE‑2026‑30849) and associated XSS flaws, urging users to update immediately. It highlights the vulnerability details but provides no PoC or exploit code.
pdnuclei-bot@pdnuclei_botDisclosure
The tweet announces the critical CVE‑2026‑30849 for MantisBT versions below 2.28.1, detailing a SOAP API authentication bypass and linking to a resource that likely provides further information.
Gumbraise.𝚟𝚞𝚎@gumbraisePoC
This GitHub repo presents a proof‑of‑concept script that demonstrates an authentication bypass vulnerability (CVE‑2026‑30849) in MantisBT's SOAP interface.
CrowdCyber 🌐@CrowdCyber_ComDisclosure
The announcement reports a high‑severity (CVSS 9.3) authentication bypass and XSS flaw (CVE‑2026‑30849) in MantisBT, but offers no PoC, exploit code, active exploitation evidence, or mitigation details.
PulsePatch.io@pulsepatchioDisclosure
The post announces CVE‑2026‑30849, an authentication bypass in MantisBT's SOAP API with MySQL, without providing PoC, exploit code, or patch details.
0day Signal@0dayPublishingDisclosure
A zero‑day authentication bypass in the MantisBT SOAP API has been disclosed, relying on MySQL string‑to‑int conversion; details are linked but no exploit code or patch is mentioned.