Mantis Bug Tracker Authorization Bypass Vulnerability Allowing Attachment Uploads to Private Issues

Vulnerability

An authorization bypass vulnerability has been identified in Mantis Bug Tracker (MantisBT) versions through 2.28.1. This vulnerability allows authenticated users to upload attachments to private issues they are not authorized to access. The issue arises from the application's permission model, which for existing issues, only checks project-level upload rights rather than issue-specific visibility. Consequently, users can upload files to private issues if they have the necessary project permissions, even if they are barred from viewing those issues.

Impact

Exploitation of this vulnerability could lead to unauthorized access to private issue content through uploaded attachments.

Reproduction

To reproduce this vulnerability, log in as a user with low privileges, such as a reporter. Create a private issue or select an existing one. Verify that access to the issue is denied. Then, send a REST API request to upload an attachment to the private issue, using the appropriate headers and session cookies to authenticate the request.

Remediation

Users can upgrade to MantisBT version 2.28.2, where this vulnerability has been fixed.

Added: May 20, 2026, 12:21 AM
Updated: May 20, 2026, 12:21 AM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
0.6
exploitability
6.2
remediation
7.7
relevance
8.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.