Vulnerability Description
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bestpractical | Request Tracker | < 5.0.10 |
Related Weaknesses (CWE)
References
- https://github.com/bestpractical/rt/releases/tag/rt-6.0.3Release Notes
- https://github.com/bestpractical/rt/security/advisories/GHSA-7rx2-x357-wv74MitigationVendor Advisory
FAQ
What is CVE-2026-44231?
CVE-2026-44231 is a vulnerability with a CVSS score of 9.1 (CRITICAL). RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerabil...
How severe is CVE-2026-44231?
CVE-2026-44231 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-44231?
Check the references section above for vendor advisories and patch information. Affected products include: Bestpractical Request Tracker.