MantisBT has an authorization bypass that allows reading attachments after losing access to a private issue (CVE-2026-34744) | HOL Guard CVE