Stored XSS Vulnerability in RT Issue Tracker by Best Practical
CVE-2026-44228
5.4MEDIUM
What is CVE-2026-44228?
A stored Cross-Site Scripting (XSS) vulnerability exists in the RT issue and ticket tracking system, affecting versions 6.0.0 through 6.0.2. This flaw allows authenticated users with sufficient permissions to inject malicious JavaScript via user-controlled data, which will trigger upon rendering the compromised page for other RT users. The vulnerability has been resolved in version 6.0.3. It is crucial for organizations using RT to update to the latest version to mitigate potential attacks.
Affected Version(s)
rt >= 6.0.0, < 6.0.3
