PatchSiren

Bestpractical CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Bestpractical CVE published 2026-07-20

CVE-2026-44231

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-20T20:16:43.797Z and has not been modified since then. CVE-2026-44231 is a critical vulnerability in the Request Tracker system, specifically affecting versions prior to 5.0.10 and 6.0.3. This vulnerability allows a privileged user, who is not an administrator, to obtain authentication credentials o [truncated]

MEDIUM Bestpractical CVE published 2026-07-20

CVE-2026-44229

CVE-2026-44229 is a Cross-Site Scripting (XSS) vulnerability in RT, an open-source issue and ticket tracking system. The vulnerability allows an authenticated user to upload content with JavaScript that can be executed in the browser sessions of other users who view or download the content. This issue affects RT versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3. Fixes are available in ver [truncated]

MEDIUM Bestpractical CVE published 2026-07-20

CVE-2026-44228

CVE-2026-44228 is a stored Cross-Site Scripting (XSS) vulnerability in RT, an open-source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, are affected. User-controlled data is rendered without proper HTML escaping, allowing an authenticated user with permission to set relevant data to inject JavaScript that executes when another RT user views the affected page [truncated]

HIGH bestpractical CVE published 2026-05-22

CVE-2026-41076

CVE-2026-41076 is a high-severity authentication bypass vulnerability affecting RT (Request Tracker), an open-source enterprise issue and ticket tracking system. The vulnerability exists in RT versions 5.0.9 and prior, as well as versions 6.0.0 through 6.0.2, specifically in deployments configured to use LDAP or Active Directory for user authentication. Under certain LDAP server configurations, an attacke [truncated]

HIGH bestpractical CVE published 2026-05-22

CVE-2026-41075

RT (Request Tracker) versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an authenticated SQL injection vulnerability. An attacker with valid credentials can supply crafted input that is incorporated into database queries without proper sanitization, potentially enabling unauthorized read or modification of data within the RT database. The vulnerability was disclosed on May 22, 2026, with a subse [truncated]

HIGH bestpractical CVE published 2026-05-22

CVE-2026-41074

CVE-2026-41074 is a Cross-Site Request Forgery (CSRF) vulnerability in RT (Request Tracker), an open-source enterprise-grade issue and ticket tracking system. The vulnerability affects versions 6.0.0 through 6.0.2 and was assigned a CVSS 3.1 score of 7.1 (HIGH severity). The issue was published on 2026-05-22 and last modified on 2026-05-26. An attacker who can induce a logged-in RT user to visit a malicio [truncated]

MEDIUM bestpractical CVE published 2026-05-22

CVE-2026-41073

CVE-2026-41073 is a spreadsheet formula injection vulnerability in RT (Request Tracker), an open-source enterprise issue and ticket tracking system. The vulnerability exists because user-controlled data in spreadsheet exports is not sanitized before being written to output files, allowing crafted values to be interpreted as formulas or macros when opened in spreadsheet applications. This affects versions [truncated]