CVE-2026-34970: MantisBT: Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked
(updated )
MantisBT allows a bugnote author to access the note’s Revisions page after losing access to the parent private issue.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-34970 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →