CVE-2026-34970 – MantisBT Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked
CVE ID :CVE-2026-34970
Published : May 20, 2026, 12:16 a.m. | 43 minutes ago
Description :Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior allow a bugnote author to access the note’s Revisions page after losing access to the parent private issue. This issue has been fixed in version 2.28.2.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…