Stored XSS Vulnerability in RT Issue Tracker by Best Practical
CVE-2026-44228

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-44228?

A stored Cross-Site Scripting (XSS) vulnerability exists in the RT issue and ticket tracking system, affecting versions 6.0.0 through 6.0.2. This flaw allows authenticated users with sufficient permissions to inject malicious JavaScript via user-controlled data, which will trigger upon rendering the compromised page for other RT users. The vulnerability has been resolved in version 6.0.3. It is crucial for organizations using RT to update to the latest version to mitigate potential attacks.

Affected Version(s)

rt >= 6.0.0, < 6.0.3

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.