CVE-2026-92796: Manticore Search 27.0.0 before 28.4.4 Multi-Statement Authorization Bypass

Published Sep 16, 2026
·
Updated

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that authenticate as administrators without plaintext recovery.

Affected Software

1 affected component
Manticore Manticore Search<28.4.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Manticore Search to a version that resolves this vulnerability.

    Fixed in 28.4.4

Event History

Sep 16, 2026
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Manticore Search deployments running version 27.0.0 through versions before 28.4.4 are affected. The issue applies where a read-only user can submit multi-statement SQL requests.

2

What access does an attacker need?

An attacker needs valid read-only credentials and network access to submit SQL requests to the affected Manticore Search service. No user interaction is required.

3

What can a read-only attacker do?

They can append additional SELECT statements after an initially permitted statement, bypassing authorization checks for those later statements. This can expose credential tables and administrator-authenticating password hashes.

4

How can I determine whether a system may already have been targeted?

Review SQL request logs for multi-statement requests submitted by read-only accounts, particularly requests containing appended SELECT statements that access credential tables. The provided data does not identify specific log fields or indicators beyond this request pattern.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203