CVE 5.3 MEDIUM

MantisBT authorization bypass allows continued access to self-uploaded attachments on private issues_CVE-2026-34744

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior permit a user to list and download their own attachments from an Issue created by another user even after it becomes private, bypassing read access revocation. The loss of confidentiality caused by this vulnerability is minimal, considering that only attachments previously uploaded by the user themselves remain accessible. This issue has been fixed in version 2.82.2.

Basic Information

ID CVE-2026-34744
Source GitHub_M
Published May 19, 2026 at 22:45

Affected Product

Vendor mantisbt
Product mantisbt
Version < 2.28.2
Affected Versions mantisbt mantisbt < 2.28.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.