Critical Security Issue in MantisBT <= 2.28.0

A critical vulnerability (CVE-2026-30849) has been identified in MantisBT 2.28.0 and earlier releases, affecting instances running on MySQL and compatible databases.

MantisBT 2.28.1 includes a fix addressing the issue and is be available since Monday, March 16th 2026. All installations are advised to upgrade immediately.

Considering the issue’s nature and high severity, this advance notice was published early to inform administrators so they can plan ahead and patch their systems before complete details about the issue became available to the general public, in the hope that exposed systems are updated before the vulnerability can be exploited. Full disclosure took place on March 23rd.

We would like to thank to Alexander Philiotis of SynerComm for discovering and responsibly reporting the issue.