PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44228 Bestpractical CVE debrief

CVE-2026-44228 is a stored Cross-Site Scripting (XSS) vulnerability in RT, an open-source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, are affected. User-controlled data is rendered without proper HTML escaping, allowing an authenticated user with permission to set relevant data to inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. RT users and administrators, especially those with versions 6.0.0 through 6.0.2, should be aware of this vulnerability and take necessary actions to protect their systems.

Vendor
Bestpractical
Product
Request Tracker
CVSS
MEDIUM 5.4
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-20
Original CVE updated
2026-08-07
Advisory published
2026-07-20
Advisory updated
2026-08-07

Who should care

RT users and administrators, especially those with versions 6.0.0 through 6.0.2, should be aware of this vulnerability and take necessary actions to protect their systems. This includes inventorying and verifying affected RT versions, applying vendor patches, monitoring for suspicious JavaScript execution, restricting user permissions for setting relevant data, and implementing additional XSS protections. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure comprehensive protection of RT deployments. RT users should review the official CVE record and vendor advisory for detailed guidance on mitigation and remediation. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retest remediated assets, and close the item only after evidence is documented. RT users should also consider tracking changes and source tracking to ensure visibility into potential attacks. RT administrators should prioritize patching affected systems and consider implementing additional security measures to prevent similar vulnerabilities in the future. RT users with versions prior to 6.0.3 should take immediate action to protect their systems. RT administrators should also review and update their incident response plans to address potential XSS attacks. RT users should be aware of the potential for JavaScript injection and take steps to prevent it. RT administrators should consider implementing additional security controls to prevent similar vulnerabilities. RT users should also review their system configurations to ensure they are not vulnerable to this issue. RT administrators should prioritize securing their RT deployments to prevent potential attacks. RT users should be cautious when interacting with RT systems that may be affected by this vulnerability. RT administrators should take steps to protect their systems and prevent potential attacks. RT users should review their system logs to detect potential attacks. RT administrators should consider implementing a web

Technical summary

The CVE-2026-44228 issue is a stored Cross-Site Scripting (XSS) vulnerability in RT, an open-source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, are affected. User-controlled data is rendered without proper HTML escaping, allowing an authenticated user with permission to set relevant data to inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.

Defensive priority

Authenticated users with permission to set relevant data can inject JavaScript that executes when another RT user views the affected page.

Recommended defensive actions

  • Inventory and verify affected RT versions 6.0.0 through 6.0.2.
  • Apply vendor patch in version 6.0.3.
  • Monitor for suspicious JavaScript execution.
  • Restrict user permissions for setting relevant data.
  • Implement additional XSS protections.

Evidence notes

The CVE-2026-44228 issue is a stored Cross-Site Scripting (XSS) vulnerability in RT, an open-source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, are affected. User-controlled data is rendered without proper HTML escaping, allowing an authenticated user with permission to set relevant data to inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T18:16:52.323Z and has not been modified since then.