CVE-2026-92796

Source
https://cve.org/CVERecord?id=CVE-2026-92796
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92796.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92796
Published
2026-09-16T20:32:50Z
Modified
2026-09-22T03:30:34Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Manticore Search 27.0.0 before 28.4.4 Multi-Statement Authorization Bypass
Details

Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL requests, allowing read-only users to execute unauthorized queries. Attackers can append additional SELECT statements after the first statement to read credential tables and obtain password hashes that authenticate as administrators without plaintext recovery.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-863"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92796.json"
}
References

Affected packages

Git / github.com/manticoresoftware/manticoresearch

Affected ranges

Type
GIT
Repo
https://github.com/manticoresoftware/manticoresearch
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "27.0.0"
        },
        {
            "fixed":  "28.4.4"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

27.*
27.0.0
27.1.0
27.1.1
27.1.2
27.1.3
27.1.4
27.1.5
27.2.0
27.3.0
27.4.0
28.*
28.0.0
28.0.1
28.0.2
28.1.0
28.1.1
28.1.2
28.1.3
28.1.4
28.1.5
28.2.0
28.3.0
28.3.1
28.3.2
28.3.3
28.3.4
28.3.5
28.3.6
28.3.7
28.4.0
28.4.1
28.4.2
28.4.3
28.4.4
Other
pack_publish

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92796.json"