CVE-2026-34970

MEDIUM

MantisBT Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked

Title source: cna
STIX 2.1

Description

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to access the note's Revisions page after losing access to the parent private issue. This issue has been fixed in version 2.28.2.

Scores

CVSS v4 5.3
EPSS 0.0037
EPSS Percentile 28.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
mantisbt/mantisbt 0 - 2.28.2Packagist
mantisbt/mantisbt < 2.28.2
Published May 20, 2026
Tracked Since May 20, 2026