Vulnerability Description
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/mantisbt/mantisbt/commit/b262b4d2835b81394d75356dead66e52a627
- https://github.com/mantisbt/mantisbt/security/advisories/GHSA-h4x5-gvx6-3rwc
- https://mantisbt.org/bugs/view.php?id=36976
FAQ
What is CVE-2026-34754?
CVE-2026-34754 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This iss...
How severe is CVE-2026-34754?
CVE-2026-34754 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-34754?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.