HIGH
manticoresoftware
CVE published 2026-09-16
CVE-2026-92796
Manticore Search versions 27.0.0 before 28.4.4 are vulnerable to an authorization bypass. The vulnerability allows read-only users to execute unauthorized queries by appending additional SELECT statements to multi-statement SQL requests. This can lead to the exposure of credential tables and the obtainment of password hashes that authenticate as administrators.