Cross-Site Scripting Vulnerability in RT Tracking System by Best Practical
CVE-2026-44229
5.4MEDIUM
What is CVE-2026-44229?
The RT ticket tracking system, an open-source solution developed by Best Practical, is susceptible to a Cross-Site Scripting (XSS) flaw in its versions 5.0.0 and 6.0.0 before the patches released in versions 5.0.10 and 6.0.3. This vulnerability arises when files uploaded by authenticated users are served inline, allowing the possibility for JavaScript execution within the browser of any RT user who accesses or downloads the content. The issue potentially compromises user sessions and data integrity, emphasizing the need for timely updates to secure versions of the software.
Affected Version(s)
rt >= 6.0.0, < 6.0.3 < 6.0.0, 6.0.3
rt >= 5.0.0, < 5.0.10 < 5.0.0, 5.0.10
