CVE-2026-44229
published 2026-07-20CVE-2026-44229: RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a…
PriorityP426medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.24%
15.0th percentile
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bestpractical | request_tracker | >= 5.0.0 < 5.0.10 | 5.0.10 |
| bestpractical | request_tracker | >= 6.0.0 < 6.0.3 | 6.0.3 |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| ubuntu | request-tracker5 | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Request Tracker vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 4.6
CVE-2026-44231 [MEDIUM] Request Tracker vulnerabilities
Title: Request Tracker vulnerabilities
Summary: Several security issues were fixed in Request Tracker.
Aleksander Iwicki discovered that Request Tracker did not properly sanitize
the search "Page" URL parameter. A remote attacker could possibly use this
issue to conduct a reflected cross-site scripting attack. (CVE-2026-6841)
It was discovered that Request Tracker did not properly sanitize user-
controlled data written to spreadsheet exports of search results. A remote
attacker could possibly use this issue to conduct a spreadsheet
(CSV/formula) injection attack, causing spreadsheet applications to
interpret crafted values as formulas or macros when the file is opened.
(CVE-2026-41073)
It was discovered that Request Tracker did not properly validate input
incorporated into database que
VulDB
Best Practical RT up to 5.0.9/6.0.2 Upload cross site scripting
vuldb·2026-07-20·CVSS 5.4
CVE-2026-44229 [MEDIUM] Best Practical RT up to 5.0.9/6.0.2 Upload cross site scripting
A vulnerability was found in Best Practical RT up to 5.0.9/6.0.2. It has been declared as problematic. The impacted element is an unknown function of the component Upload. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-44229. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44229 rt: cross-site scripting via inline-served uploaded content [fedora-all]
bugzilla·2026-07-20·CVSS 5.4
CVE-2026-44229 [MEDIUM] CVE-2026-44229 rt: cross-site scripting via inline-served uploaded content [fedora-all]
CVE-2026-44229 rt: cross-site scripting via inline-served uploaded content [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3
Bugzilla
CVE-2026-44229 rt: cross-site scripting via inline-served uploaded content
bugzilla·2026-07-20·CVSS 5.4
CVE-2026-44229 [MEDIUM] CVE-2026-44229 rt: cross-site scripting via inline-served uploaded content
CVE-2026-44229 rt: cross-site scripting via inline-served uploaded content
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.
2026-07-20
Published