CVE-2026-44227
Last modified
CVE-2026-44227 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability. An attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. There are no effective workarounds. Avoid following untrusted RT URLs. This issue has been fixed in version 6.0.3.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bestpractical | Request Tracker | >= 6.0.0, < 6.0.3 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-44227?
How severe is CVE-2026-44227?
How do I fix CVE-2026-44227?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-44221ArcadeDB is a Multi-Model DBMS. Starting in version 21.10.1 …9
- CVE-2026-44222vLLM is an inference and serving engine for large language m…7.5
- CVE-2026-44223vLLM is an inference and serving engine for large language m…6.5
- CVE-2026-44224Wiki.js is an open source wiki app built on Node.js. Prior t…8.8
- CVE-2026-44225Pulpy is a lightweight, cross-platform desktop application p…9.3
- CVE-2026-44226pyLoad is a free and open-source download manager written in…5.3
- CVE-2026-44228RT is an open source, enterprise-grade issue and ticket trac…5.4
- CVE-2026-44229RT is an open source, enterprise-grade issue and ticket trac…5.4
- CVE-2026-44230RT is an open source, enterprise-grade issue and ticket trac…6.1
- CVE-2026-44231RT is an open source, enterprise-grade issue and ticket trac…9.1
- CVE-2026-44232DSSRF is a Node.js library that provides a wide range of uti…8.7
- CVE-2026-44237FreePBX is an open source IP PBX. Prior to 17.0.8, the FreeP…8.1
Are you affected by CVE-2026-44227?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
