CVE-2026-33052Disclosure

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add_profile_threshold" permission to create a global profile despite not having manage_global_profile_threshold, by tampering with the user_id parameter in a valid profile creation request. This issue has been fixed in version 2.28.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-05-19: 2Technical Details · 2026-05-19: 105-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33052 Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add_profile_threshol… https://www.cve.org/CVERecord?id=CVE-2026-33052

    Post summary

    The statement announces a new CVE (CVE‑2026‑33052) affecting Mantis Bug Tracker versions 2.28.0 and 2.28.1, noting that a low‑privileged authenticated user can perform an action, but provides no PoC, exploit code, or patch details.

    00000161
    57.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33052 Privilege Escalation in Mantis Bug Tracker 2.28.0 and 2.28.1 via Parameter Tampering https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33052

    Post summary

    The text announces CVE-2026-33052, a privilege escalation vulnerability in Mantis Bug Tracker 2.28.0 and 2.28.1 caused by parameter tampering.

    0000068
    4.0K followersView on X

Explore more