CVE 4.3 MEDIUM

MantisBT allows unauthorized users to upload attachments to restricted issues via REST API_CVE-2026-34754

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.

Basic Information

ID CVE-2026-34754
Source GitHub_M
Published May 19, 2026 at 23:05

Affected Product

Vendor mantisbt
Product mantisbt
Version < 2.28.2
Affected Versions mantisbt mantisbt < 2.28.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.