Junglewise Threat Intelligence

CVE-2026-34970: MantisBT information disclosure in bugnote revisions page

CVE-2026-34970 · Severity: medium · CVSS 4 · Published 2026-05-20

Technologies: MantisBT Mantis Bug Tracker, mantisbt/mantisbt (Packagist). Vendors: MantisBT, Packagist.

Executive brief

MantisBT, a popular open-source bug tracking system, contains a vulnerability where users can still view certain details of private issues even after their access has been revoked. Specifically, if a user previously authored a note on an issue, they can still access that note's revision history to see the private issue's ID and summary. This could lead to the unauthorized disclosure of sensitive project metadata or internal ticket titles.

Technical details

An information disclosure vulnerability exists in MantisBT due to improper access control on the Bugnote Revision page. When an issue is marked as private or a user's access to an issue is revoked, the system fails to restrict access to the revision history for users who were the original authors of notes (bugnotes) on that issue. By navigating to the revision page of their own previous notes, an unauthorized user can view the parent issue's ID and Summary metadata. The full body of the revisions remains protected, but the metadata leakage violates the privacy settings of the parent issue. This is fixed in version 2.28.2.

Affected products

  • MantisBT MantisBT <= 2.28.1

Timeline

  • 2026-05-09: disclosed: Initial disclosure by researcher
  • 2026-05-11: advisory: GitHub Advisory published
  • 2026-05-20: other: NVD published date

References

Related threats