MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST API (CVE-2026-34754) | HOL Guard CVE