VDB

CVE-2026-44231

CVE-2026-44231 PUBLISHED CVSS 9.1 CRITICAL

Reported by GitHub_M · Published July 20, 2026

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.

Risk Scores

CVSS 3.1
9.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Affected Products

VendorProductVersions
bestpracticalrt< 5.0.10, >= 6.0.0, < 6.0.3
bestpracticalrt< 5.0.10, >= 6.0.0, < 6.0.3, < 5.0.10

Timeline

  • May 21, 2026 CVE Published
  • Jul 20, 2026 Coalition ESS Score
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›