All verified exploits

CVE-2026-30849 SOAP API Authentication Bypass via Type Juggling

Deterministic critical MantisBT Added cve-verified-cve-2026-30849

Detects MantisBT instances running on MySQL where the SOAP API's mc_login function accepts passwords as integers instead of strings. By sending the password as xsd:integer 0, MySQL's implicit type conversion causes the stored password hash to compare equal to 0, bypassing authentication entirely. An attacker who knows any username gains full API access. All versions before 2.28.1 on MySQL backends are affected.

Is your app exploitable through CVE-2026-30849?

Scan your domain free