PatchSiren cyber security CVE debrief
CVE-2026-44228 Bestpractical CVE debrief
CVE-2026-44228 is a stored Cross-Site Scripting (XSS) vulnerability in RT, an open-source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, are affected. User-controlled data is rendered without proper HTML escaping, allowing an authenticated user with permission to set relevant data to inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. RT users and administrators, especially those with versions 6.0.0 through 6.0.2, should be aware of this vulnerability and take necessary actions to protect their systems.
- Vendor
- Bestpractical
- Product
- Request Tracker
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-08-07
Who should care
RT users and administrators, especially those with versions 6.0.0 through 6.0.2, should be aware of this vulnerability and take necessary actions to protect their systems. This includes inventorying and verifying affected RT versions, applying vendor patches, monitoring for suspicious JavaScript execution, restricting user permissions for setting relevant data, and implementing additional XSS protections. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure comprehensive protection of RT deployments. RT users should review the official CVE record and vendor advisory for detailed guidance on mitigation and remediation. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retest remediated assets, and close the item only after evidence is documented. RT users should also consider tracking changes and source tracking to ensure visibility into potential attacks. RT administrators should prioritize patching affected systems and consider implementing additional security measures to prevent similar vulnerabilities in the future. RT users with versions prior to 6.0.3 should take immediate action to protect their systems. RT administrators should also review and update their incident response plans to address potential XSS attacks. RT users should be aware of the potential for JavaScript injection and take steps to prevent it. RT administrators should consider implementing additional security controls to prevent similar vulnerabilities. RT users should also review their system configurations to ensure they are not vulnerable to this issue. RT administrators should prioritize securing their RT deployments to prevent potential attacks. RT users should be cautious when interacting with RT systems that may be affected by this vulnerability. RT administrators should take steps to protect their systems and prevent potential attacks. RT users should review their system logs to detect potential attacks. RT administrators should consider implementing a web
Technical summary
The CVE-2026-44228 issue is a stored Cross-Site Scripting (XSS) vulnerability in RT, an open-source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, are affected. User-controlled data is rendered without proper HTML escaping, allowing an authenticated user with permission to set relevant data to inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.
Defensive priority
Authenticated users with permission to set relevant data can inject JavaScript that executes when another RT user views the affected page.
Recommended defensive actions
- Inventory and verify affected RT versions 6.0.0 through 6.0.2.
- Apply vendor patch in version 6.0.3.
- Monitor for suspicious JavaScript execution.
- Restrict user permissions for setting relevant data.
- Implement additional XSS protections.
Evidence notes
The CVE-2026-44228 issue is a stored Cross-Site Scripting (XSS) vulnerability in RT, an open-source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, are affected. User-controlled data is rendered without proper HTML escaping, allowing an authenticated user with permission to set relevant data to inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-44228 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-44228
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-44228 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44228
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/bestpractical/rt/releases/tag/rt-6.0.3
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/bestpractical/rt/security/advisories/GHSA-pfgp-5j8g-phgc
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.