Critical Security Issue in MantisBT <= 2.28.3

A critical vulnerability (CVE-2026-47156) has been identified in MantisBT 2.28.3 and earlier releases.

It will be fixed in Version 2.28.4, together with several other security issues, and will be available on Wednesday, July 1st 2026, around 12:00 UTC. Be ready to patch your system right away ! All installations are advised to upgrade as quickly as possible.

Considering the issue’s nature and high severity, we are publishing this advance notice to inform administrators so they can plan ahead and patch their systems before complete details about the issue become available to the general public, in the hope that exposed systems are updated before the vulnerability can be exploited. Full disclosure is expected to take place on July 6th.

We would like to thank McCaulay Hudson of watchTowr for originally identifying and responsibly reporting the issue.

The vulnerability was subsequently discovered by other researchers, while we were working on fixing it and preparing the release. We credit them here, in chronological order of their reports: Keitaro Yamazaki (tyage), Harrison Keating (voraci0us), Chandler Johnson (chndlrx) and Bharat Devasani (bharatdevasani).