CVE-2026-44231
Reported by GitHub_M · Published July 20, 2026
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| bestpractical | rt | < 5.0.10, >= 6.0.0, < 6.0.3 |
| bestpractical | rt | < 5.0.10, >= 6.0.0, < 6.0.3, < 5.0.10 |
Timeline
- May 21, 2026 CVE Published
- Jul 20, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- https://github.com/bestpractical/rt/security/advisories/GHSA-7rx2-x357-wv74 x_refsource_CONFIRM
- https://github.com/bestpractical/rt/releases/tag/rt-6.0.3 x_refsource_MISC