๐Ÿ” CVE Alert

CVE-2026-34754

MEDIUM 4.3

MantisBT allows unauthorized users to upload attachments to restricted issues via REST API

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
7th

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.

CWE CWE-284
Vendor mantisbt
Product mantisbt
Published May 19, 2026
Last Updated May 20, 2026
Stay Ahead of the Next One

Get instant alerts for mantisbt mantisbt

Be the first to know when new medium vulnerabilities affecting mantisbt mantisbt are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

mantisbt / mantisbt
< 2.28.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/mantisbt/mantisbt/security/advisories/GHSA-h4x5-gvx6-3rwc github.com: https://github.com/mantisbt/mantisbt/commit/b262b4d2835b81394d75356dead66e52a6275206 mantisbt.org: https://mantisbt.org/bugs/view.php?id=36976