MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST API
Description
Published to the GitHub Advisory Database
May 11, 2026
Reviewed
May 11, 2026
Last updated
May 11, 2026
Impact
MantisBT allows an authenticated user to upload attachments to private Issues they are not authorized to access.
Patches
Workarounds
None.
Credits
Thanks to Vishal Shukla for discovering and responsibly reporting the issue.
References