PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44655 mantisbt CVE debrief

Mantis Bug Tracker (MantisBT) versions 1.3.0 through 2.28.1 contain a stored cross-site scripting (XSS) vulnerability in the Project Name field. An attacker with manager or administrator privileges can inject malicious HTML into the Project Name, which renders unescaped on the Move Attachments administrative page. This allows execution of arbitrary scripts in the context of other administrators' sessions. The vulnerability stems from insufficient output encoding when displaying project names in this specific administrative interface. The CVSS 4.0 score of 8.6 reflects high impact to confidentiality, integrity, and availability, though the attack requires high privileges (PR:H). The issue was remediated in version 2.28.2 via proper HTML escaping.

Vendor
mantisbt
Product
Unknown
CVSS
HIGH 8.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-07-21
Advisory published
2026-05-28
Advisory updated
2026-07-21

Who should care

MantisBT administrators and security teams managing issue tracking infrastructure. Organizations with delegated project management responsibilities where lower-privileged managers may have project configuration access. Security auditors reviewing web application access controls and output encoding implementations.

Technical summary

The vulnerability exists in MantisBT's handling of Project Name display on the Move Attachments administration page. The application fails to apply HTML entity encoding when rendering project names in this specific context, permitting injection of arbitrary HTML and JavaScript. The attack surface is constrained to users with elevated privileges (manager or administrator) who can modify project configuration. The fix in commit 5cb4b469295889f5d2b01677c9bf82c143e0fdaa implements proper escaping to neutralize injected markup.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade MantisBT to version 2.28.2 or later to remediate this vulnerability.
  • Review and audit Project Name values in existing MantisBT installations for unexpected HTML or script content.
  • Implement principle of least privilege by limiting manager and administrator account assignments.
  • Enable Content Security Policy (CSP) headers as a defense-in-depth measure to mitigate impact of any residual XSS vectors.
  • Monitor administrative access logs for unusual Project Name modification activity.

Evidence notes

Vulnerability affects MantisBT 1.3.0 to 2.28.1. Fixed in 2.28.2. Attack requires manager/administrator access to modify Project Name. CWE-79 (Improper Neutralization of Input During Web Page Generation). CVSS 4.0 vector: AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44655 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44655

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44655 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44655

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.