Cross-Site Scripting Vulnerability in RT Tracking System by Best Practical
CVE-2026-44229

5.4MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-44229?

The RT ticket tracking system, an open-source solution developed by Best Practical, is susceptible to a Cross-Site Scripting (XSS) flaw in its versions 5.0.0 and 6.0.0 before the patches released in versions 5.0.10 and 6.0.3. This vulnerability arises when files uploaded by authenticated users are served inline, allowing the possibility for JavaScript execution within the browser of any RT user who accesses or downloads the content. The issue potentially compromises user sessions and data integrity, emphasizing the need for timely updates to secure versions of the software.

Affected Version(s)

rt >= 6.0.0, < 6.0.3 < 6.0.0, 6.0.3

rt >= 5.0.0, < 5.0.10 < 5.0.0, 5.0.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.