Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.
References
Configurations
No configuration.
History
20 May 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-20 00:16
Updated : 2026-05-20 14:06
NVD link : CVE-2026-34754
Mitre link : CVE-2026-34754
CVE.ORG link : CVE-2026-34754
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
