PatchSiren cyber security CVE debrief
CVE-2026-40598 mantisbt CVE debrief
CVE-2026-40598 is a medium-severity vulnerability affecting Mantis Bug Tracker (MantisBT) versions 2.28.1 and below. The issue involves improper escaping of the redirection page, which can lead to cross-site scripting (XSS) under specific server configurations. This vulnerability allows an attacker to inject HTML, potentially leading to XSS. While modern browsers typically URL-encode special characters, certain server configurations may be vulnerable to cache poisoning and subsequent XSS exploitation.
- Vendor
- mantisbt
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-22
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-22
- Advisory updated
- 2026-07-23
Who should care
Users of Mantis Bug Tracker (MantisBT) versions 2.28.1 and below should apply the patch to prevent potential XSS attacks. Operators, platform administrators, vulnerability management teams, and security teams should review the vulnerability and apply necessary mitigations.
Technical summary
The vulnerability exists due to improper escaping of the redirection page retrieved from the request's Referer header. This allows an attacker to inject HTML, potentially leading to XSS. While modern browsers typically URL-encode special characters, certain server configurations may be vulnerable to cache poisoning and subsequent XSS exploitation. Affected product deployments should be reviewed for exposure.
Defensive priority
Apply the patch to prevent potential XSS attacks. Review and update server configurations as necessary.
Recommended defensive actions
- Apply the patch to Mantis Bug Tracker (MantisBT) versions 2.28.1 and below.
- Review server configurations for potential vulnerabilities.
- Monitor for suspicious activity.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-05-22T20:16:34.490Z and last modified on 2026-07-23T16:10:00.137Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD details. Defenders should verify Mantis Bug Tracker (MantisBT) versions and configurations.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-22T20:16:34.490Z and has not been modified since then. The NVD entry is currently Deferred.