PatchSiren cyber security CVE debrief
CVE-2026-44228 Bestpractical CVE debrief
CVE-2026-44228 is a stored Cross-Site Scripting (XSS) vulnerability in RT, an open-source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, are affected. User-controlled data is rendered without proper HTML escaping, allowing an authenticated user with permission to set relevant data to inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3. The vulnerability has a CVSS score of 5.4 and a severity of MEDIUM. RT users and administrators, especially those with versions 6.0.0 through 6.0.2, should be aware of this vulnerability and take necessary actions to protect their systems.
- Vendor
- Bestpractical
- Product
- Request Tracker
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-20
- Original CVE updated
- 2026-08-07
- Advisory published
- 2026-07-20
- Advisory updated
- 2026-08-07
Who should care
RT users and administrators, especially those with versions 6.0.0 through 6.0.2, should be aware of this vulnerability and take necessary actions to protect their systems. This includes inventorying and verifying affected RT versions, applying vendor patches, monitoring for suspicious JavaScript execution, restricting user permissions for setting relevant data, and implementing additional XSS protections. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated to ensure comprehensive protection of RT deployments. RT users should review the official CVE record and vendor advisory for detailed guidance on mitigation and remediation. Compensating controls for exposed systems should be reviewed while remediation is scheduled and verified. Relevant monitoring, detection, and logs for exposed assets should be checked for extra review. Exceptions, retest remediated assets, and close the item only after evidence is documented. RT users should also consider tracking changes and source tracking to ensure visibility into potential attacks. RT administrators should prioritize patching affected systems and consider implementing additional security measures to prevent similar vulnerabilities in the future. RT users with versions prior to 6.0.3 should take immediate action to protect their systems. RT administrators should also review and update their incident response plans to address potential XSS attacks. RT users should be aware of the potential for JavaScript injection and take steps to prevent it. RT administrators should consider implementing additional security controls to prevent similar vulnerabilities. RT users should also review their system configurations to ensure they are not vulnerable to this issue. RT administrators should prioritize securing their RT deployments to prevent potential attacks. RT users should be cautious when interacting with RT systems that may be affected by this vulnerability. RT administrators should take steps to protect their systems and prevent potential attacks. RT users should review their system logs to detect potential attacks. RT administrators should consider implementing a web
Technical summary
The CVE-2026-44228 issue is a stored Cross-Site Scripting (XSS) vulnerability in RT, an open-source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, are affected. User-controlled data is rendered without proper HTML escaping, allowing an authenticated user with permission to set relevant data to inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.
Defensive priority
Authenticated users with permission to set relevant data can inject JavaScript that executes when another RT user views the affected page.
Recommended defensive actions
- Inventory and verify affected RT versions 6.0.0 through 6.0.2.
- Apply vendor patch in version 6.0.3.
- Monitor for suspicious JavaScript execution.
- Restrict user permissions for setting relevant data.
- Implement additional XSS protections.
Evidence notes
The CVE-2026-44228 issue is a stored Cross-Site Scripting (XSS) vulnerability in RT, an open-source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, are affected. User-controlled data is rendered without proper HTML escaping, allowing an authenticated user with permission to set relevant data to inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.
Official resources
-
CVE-2026-44228 CVE record
CVE.org
-
CVE-2026-44228 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Release Notes
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T18:16:52.323Z and has not been modified since then.