{"api_version":"1","generated_at":"2026-05-30T01:00:04+00:00","cve":"CVE-2026-34754","urls":{"html":"https://cve.report/CVE-2026-34754","api":"https://cve.report/api/cve/CVE-2026-34754.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-34754","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-34754"},"summary":{"title":"MantisBT allows unauthorized users to upload attachments to restricted issues via REST API","description":"Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.","state":"PUBLISHED","assigner":"GitHub_M","published_at":"2026-05-20 00:16:34","updated_at":"2026-05-20 14:06:33"},"problem_types":["CWE-284","CWE-284 CWE-284: Improper Access Control"],"metrics":[{"version":"3.1","source":"security-advisories@github.com","type":"Secondary","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"4.3","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://github.com/mantisbt/mantisbt/commit/b262b4d2835b81394d75356dead66e52a6275206","name":"https://github.com/mantisbt/mantisbt/commit/b262b4d2835b81394d75356dead66e52a6275206","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://mantisbt.org/bugs/view.php?id=36976","name":"https://mantisbt.org/bugs/view.php?id=36976","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-h4x5-gvx6-3rwc","name":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-h4x5-gvx6-3rwc","refsource":"security-advisories@github.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-34754","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-34754","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"mantisbt","product":"mantisbt","version":"affected < 2.28.2","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"34754","cve":"CVE-2026-34754","epss":"0.000280000","percentile":"0.083210000","score_date":"2026-05-27","updated_at":"2026-05-28 00:02:14"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"product":"mantisbt","vendor":"mantisbt","versions":[{"status":"affected","version":"< 2.28.2"}]}],"descriptions":[{"lang":"en","value":"Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-05-19T23:05:27.818Z","orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M"},"references":[{"name":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-h4x5-gvx6-3rwc","tags":["x_refsource_CONFIRM"],"url":"https://github.com/mantisbt/mantisbt/security/advisories/GHSA-h4x5-gvx6-3rwc"},{"name":"https://github.com/mantisbt/mantisbt/commit/b262b4d2835b81394d75356dead66e52a6275206","tags":["x_refsource_MISC"],"url":"https://github.com/mantisbt/mantisbt/commit/b262b4d2835b81394d75356dead66e52a6275206"},{"name":"https://mantisbt.org/bugs/view.php?id=36976","tags":["x_refsource_MISC"],"url":"https://mantisbt.org/bugs/view.php?id=36976"}],"source":{"advisory":"GHSA-h4x5-gvx6-3rwc","discovery":"UNKNOWN"},"title":"MantisBT allows unauthorized users to upload attachments to restricted issues via REST API"}},"cveMetadata":{"assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","assignerShortName":"GitHub_M","cveId":"CVE-2026-34754","datePublished":"2026-05-19T23:05:27.818Z","dateReserved":"2026-03-30T19:17:10.225Z","dateUpdated":"2026-05-19T23:05:27.818Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-05-20 00:16:34","lastModifiedDate":"2026-05-20 14:06:33","problem_types":["CWE-284","CWE-284 CWE-284: Improper Access Control"],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"34754","Ordinal":"1","Title":"MantisBT allows unauthorized users to upload attachments to rest","CVE":"CVE-2026-34754","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"34754","Ordinal":"1","NoteData":"Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow an authenticated user to upload attachments to private Issues they are not authorized to access. This issue has been fixed in version 2.28.2.","Type":"Description","Title":"MantisBT allows unauthorized users to upload attachments to rest"}]}}}