PatchSiren

manticoresoftware CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH manticoresoftware CVE published 2026-09-16

CVE-2026-92796

Manticore Search versions 27.0.0 before 28.4.4 are vulnerable to an authorization bypass. The vulnerability allows read-only users to execute unauthorized queries by appending additional SELECT statements to multi-statement SQL requests. This can lead to the exposure of credential tables and the obtainment of password hashes that authenticate as administrators.