DevSecOps Toolkit

CVE record

CVE-2026-34754

MEDIUMCVSS 4.3

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.

Vulnerability metadata

Published
2026-05-19T18:46:34.857Z
Modified
2026-05-20T08:36:33.993Z
EPSS
Not available
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

References