Description
Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that authenticate as administrators without plaintext recovery.
Published: 2026-09-16
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass leading to credential compromise
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows a user with read‑only permissions to append additional SELECT statements to an authorized query. Because the system only verifies the authorization of the first statement, the subsequent statements are executed with the same privileges. An attacker can thus retrieve credential tables and obtain password hashes for administrative accounts. This results in credential compromise and elevation of privileges with potential system‑wide impact.

Affected Systems

Manticore Software’s Manticore Search product is vulnerable in all releases from 27.0.0 up to and including 28.4.3. The issue is present in the source code that handles MySQL protocol authentication and query parsing, as shown in the file auth_proto_mysql.cpp around line 408–418 in the 28.4.4 source tree.

Risk and Exploitability

The CVSS base score of 8.7 indicates high severity. However, the EPSS score is below 1 %, meaning the probability of exploitation in the wild is low, and the vulnerability is not yet listed in the CISA KEV catalog. The most likely attack path involves an authenticated read‑only user submitting a crafted multi‑statement request that bypasses authorization checks on the subsequent SELECT clause. Because only authorization is improperly enforced, a successful request can give an attacker access to sensitive credential data without requiring elevated privileges.

Generated by OpenCVE AI on September 18, 2026 at 05:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Manticore Search to version 28.4.4 or later, which contains the authorization checks for all statements in a multi‑statement request.
  • Review configuration settings to disable support for multi‑statement queries if they are not required by your application.
  • Ensure that read‑only user accounts are not granted SELECT privileges on credential tables and that all user permissions are audited for consistency.

Generated by OpenCVE AI on September 18, 2026 at 05:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Manticoresoftware
Manticoresoftware manticore Search
Vendors & Products Manticoresoftware
Manticoresoftware manticore Search

Wed, 16 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that authenticate as administrators without plaintext recovery.
Title Manticore Search 27.0.0 before 28.4.4 Multi-Statement Authorization Bypass
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Manticoresoftware Manticore Search
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T15:43:07.203Z

Reserved: 2026-09-16T19:40:21.263Z

Link: CVE-2026-92796

cve-icon Vulnrichment

Updated: 2026-09-21T15:43:02.943Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T21:17:29.377

Modified: 2026-09-22T20:53:07.383

Link: CVE-2026-92796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T20:03:08Z

Weaknesses