CVE Database
/

CVE-2026-33052

Back to search

CVE-2026-33052

Published: May 19, 2026

Modified: May 19, 2026

PUBLISHED

Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add_profile_threshold" permission to create a global profile despite not having manage_global_profile_threshold, by tampering with the user_id parameter in a valid profile creation request. This issue has been fixed in version 2.28.2.

VendorProductVersions

mantisbt

mantisbt

affected
>= 2.28.0, < 2.28.2

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now