mantisbt - Change Log
Released 2026-07-01
Maintenance and Security release addressing a critical authentication bypass vulnerability in the SOAP API (CVE-2026-47156, thanks to MacCaulay Hudson of watchTowr) as well as 7 other vulnerabilities including SQL injection, remote code execution, Cross-site scripting, missing authorisation and improper input validation (refer to issues in the Change Log for details and security researchers credits). This release also fixes a few bugs, including a regression introduced in 2.28.2.
- 0037121: [security] CVE-2026-47156: SOAP API Authentication Bypass -> Privilege Escalation to Administrator (dregad)
- 0037065: [security] CVE-2026-52882: REST and SOAP API Issue Update Accepts Unreleased Product Versions From Updaters (community)
- 0037123: [security] CVE-2026-47142: SQL Injection via
history_orderConfiguration Value (dregad) - 0037103: [security] CVE-2026-52847/CVE-2026-52881: Reflected XSS via Multiple Parameters in
admin/install.php(dregad) - 0037122: [security] CVE-2026-49273: Remote Code Execution via
eval()Class Hoisting in Admin Configuration Set (dregad) - 0037181: [security] CVE-2026-49280: REST and SOAP APIs allows UPDATER users to change issue status despite $g_update_bug_status_threshold (dregad)
- 0037200: [security] CVE-2026-52883: Injection of TIME_TRACKING and REMINDER Notes via REST and SOAP APIs (dregad)
- 0037234: [security] CVE-2026-62944: Stored HTML injection via unescaped attachment filename extension in HTML export (dregad)
- 0037237: [printing] Printing an issue having notes without text triggers PHP error (dregad)
- 0037250: [ui] The news_list_page.php page does not display news for “All Projects” (community)
- 0037256: [email] Incorrect log message regarding sent email (community)
- 0037075: [api soap] SOAP Issue Update Implicitly Reassigns Reporter To The Caller When reporter Is Omitted (dregad)
- 0037135: [authentication] Fix CSRF validation failure in anonymous login (community)
- 0037257: [ui] Incorrect identification of a non-default mention tag (dregad)
14 issues View Issues