CVE-2026-92796 PUBLISHED

Manticore Search 27.0.0 before 28.4.4 Multi-Statement Authorization Bypass

Assigner: VulnCheck
Reserved: 16.09.2026 Published: 16.09.2026 Updated: 16.09.2026

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that authenticate as administrators without plaintext recovery.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor manticoresoftware
Product Manticore Search
Versions Default: unaffected
  • affected from 27.0.0 to 28.4.4 (excl.)

Credits

  • George Chen finder

References

Problem Types

  • Incorrect Authorization CWE