{"id":"CVE-2026-34744","aliases":["GHSA-rmp5-5jj7-gmvf"],"url":"https://o3.security/vulnerability/CVE-2026-34744","summary":"MantisBT authorization bypass allows continued access to self-uploaded attachments on private issues","details":"MantisBT permits a user to list and download their own attachments from an Issue created by another user, even after that Issue becomes private and direct access to it is denied.\n\n### Impact\nThe loss of confidentiality caused by this vulnerability is minimal, considering that only the attachments that were previously uploaded by the user themselves remains accessible.\n\n### Patches\n- de7bdeec36de066235e38a77bf056917d951c84d\n\n### Workarounds\nNone.\n\n### Credits\n\nThanks to Vishal Shukla for discovering and responsibly reporting the issue.","published":"2026-05-19T22:45:35.012Z","modified":"2026-08-12T03:51:44.034175234Z","cvss":null,"epss":{"score":0.00362,"percentile":0.29377,"asOf":"2026-08-15"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"mantisbt/mantisbt","fixedVersion":"2.28.2"}],"fix":{"url":"https://github.com/mantisbt/mantisbt/commit/de7bdeec36de066235e38a77bf056917d951c84d","label":"mantisbt/mantisbt@de7bdee"},"references":[{"type":"WEB","url":"https://mantisbt.org/bugs/view.php?id=36977"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/34xxx/CVE-2026-34744.json"},{"type":"ADVISORY","url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-rmp5-5jj7-gmvf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34744"},{"type":"FIX","url":"https://github.com/mantisbt/mantisbt/commit/de7bdeec36de066235e38a77bf056917d951c84d"},{"type":"PACKAGE","url":"https://github.com/mantisbt/mantisbt"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.034175234Z"}}