CVE-2026-44230
published 2026-07-20CVE-2026-44230: RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including)…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.26%
17.9th percentile
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. This issue has been fixed in versions 5.0.10 and 6.0.3.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bestpractical | request_tracker | >= 5.0.4 < 5.0.10 | 5.0.10 |
| bestpractical | request_tracker | >= 6.0.0 < 6.0.3 | 6.0.3 |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| ubuntu | request-tracker5 | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Request Tracker vulnerabilities
vendor_ubuntu·2026-07-06·CVSS 4.6
CVE-2026-44231 [MEDIUM] Request Tracker vulnerabilities
Title: Request Tracker vulnerabilities
Summary: Several security issues were fixed in Request Tracker.
Aleksander Iwicki discovered that Request Tracker did not properly sanitize
the search "Page" URL parameter. A remote attacker could possibly use this
issue to conduct a reflected cross-site scripting attack. (CVE-2026-6841)
It was discovered that Request Tracker did not properly sanitize user-
controlled data written to spreadsheet exports of search results. A remote
attacker could possibly use this issue to conduct a spreadsheet
(CSV/formula) injection attack, causing spreadsheet applications to
interpret crafted values as formulas or macros when the file is opened.
(CVE-2026-41073)
It was discovered that Request Tracker did not properly validate input
incorporated into database que
VulDB
Best Practical RT up to 5.0.9/6.0.2 URL cross site scripting
vuldb·2026-07-20·CVSS 6.1
CVE-2026-44230 [MEDIUM] Best Practical RT up to 5.0.9/6.0.2 URL cross site scripting
A vulnerability was found in Best Practical RT up to 5.0.9/6.0.2. It has been rated as problematic. This affects an unknown function of the component URL Handler. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-44230. The attack can be initiated remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44230 rt: reflected cross-site scripting in search results chart [fedora-all]
bugzilla·2026-07-20·CVSS 6.1
CVE-2026-44230 [MEDIUM] CVE-2026-44230 rt: reflected cross-site scripting in search results chart [fedora-all]
CVE-2026-44230 rt: reflected cross-site scripting in search results chart [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. This issue has been fixed in versions 5.0.10 and 6.0.3.
Bugzilla
CVE-2026-44230 rt: reflected cross-site scripting in search results chart
bugzilla·2026-07-20·CVSS 6.1
CVE-2026-44230 [MEDIUM] CVE-2026-44230 rt: reflected cross-site scripting in search results chart
CVE-2026-44230 rt: reflected cross-site scripting in search results chart
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. This issue has been fixed in versions 5.0.10 and 6.0.3.
2026-07-20
Published