Mantis Bug Tracker Authorization Bypass Vulnerability Allowing Access to Private Issue Attachments

Vulnerability

An authorization bypass vulnerability has been identified in Mantis Bug Tracker (MantisBT) versions through 2.28.1. This vulnerability allows users to list and download their own attachments from issues created by others, even after those issues have been made private, thereby bypassing read access restrictions. The vulnerability arises because the attachment visibility logic allows users to retain access to their own files, despite losing visibility of the parent issue.

Impact

Exploitation of this vulnerability leads to unauthorized access to private issue attachments, although the impact is limited to files uploaded by the user themselves.

Reproduction

To reproduce this vulnerability, log in as a low-privileged user and upload a file to a public issue. Once the file is uploaded, change the issue's status to private. After confirming that access to the issue is denied, use the REST API to list the issue's attachments and download the file using the file download endpoint. This process can be automated with a simple script.

Remediation

Users can upgrade to MantisBT version 2.28.2, where this vulnerability has been fixed.

Added: May 19, 2026, 11:24 PM
Updated: May 19, 2026, 11:24 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
6.2
remediation
7.7
relevance
8.8
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.