CVE-2026-30849 is an authentication bypass in the Mantis Bug Tracker (MantisBT) SOAP API affecting versions before 2.28.1 when deployed with a MySQL-family database. Improper type checking of the SOAP password parameter permits PHP SOAP deserialization to pass an attacker-controlled integer into password-verification logic. MySQL implicitly converts the stored password-hash string to a numeric value when it is compared with that integer. A hash beginning with a non-numeric character can evaluate to zero, allowing an attacker-supplied integer zero to satisfy the password comparison and be accepted as the specified user.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone TypeScript proof-of-concept for CVE-2026-30849 affecting MantisBT's SOAP interface. It is not part of a larger exploit framework. The repository contains one substantive code file (CVE-2026-30849.ts), a README with usage examples, and standard Node/TypeScript project files (package.json, package-lock.json, tsconfig.json, .gitignore). The main script supports two modes: 'check' and 'exploit'. In check mode, it appends /api/soap/mantisconnect.php to a user-supplied base URL, sends a SOAP mc_version request using curl via Node's spawnSync, extracts the returned version from the XML response, and compares it against the hardcoded patched version 2.28.1. If the detected version is lower, it prints VULNERABLE; otherwise NOT VULNERABLE. This makes the script partly a detection utility. In exploit mode, it sends a crafted SOAP mc_issue_add request to the same endpoint. The request uses hardcoded credentials fields, notably a password typed as xsd:int with value 0, and includes a fully populated IssueData structure. The intended capability is unauthorized issue creation through an authentication bypass in the SOAP API. If successful, the exploit would create a ticket with fixed metadata such as project ID 7, category ID 2319, handler ID 168/name KLR, and a custom field named 'Type d'action' set to 'Exploitation'. The script then prints the raw SOAP response. Operationally, the exploit is basic but functional: it requires curl to be installed locally, uses synchronous child-process execution, and does not provide payload customization beyond editing the source. There is no shell payload, code execution, persistence, or post-exploitation logic; the primary impact is unauthorized API action against a remote MantisBT instance. The hardcoded object IDs and field names suggest it was tested against a specific environment and may need modification for broader reuse.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The content only identifies CVE-2026-30849 in the context of adding a template; it provides no technical details about the affected product, vulnerability type, impact, or severity.
A type-juggling authentication bypass vulnerability caused by PHP SOAP deserialization producing integer types and MySQL implicitly converting stored password hashes to numeric values during comparison, allowing an attacker to supply 0 and bypass password validation.
An authentication bypass vulnerability in the MantisBT SOAP API affecting versions prior to 2.28.1 on MySQL-family databases, caused by improper type checking on the password parameter.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.