CVE-2026-44231

EUVD-2026-46079
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GitHub_MCNA
9.1 CRITICAL
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
bestpracticalrt
𝑥
< 5.0.10
CNA
Debian logo
Debian Releases
Debian Product
Codename
request-tracker4
bookworm
4.4.6+dfsg-1.1+deb12u4
fixed
bookworm (security)
4.4.6+dfsg-1.1+deb12u4
fixed
bullseye
vulnerable
bullseye (security)
vulnerable
request-tracker5
bookworm
5.0.3+dfsg-3~deb12u6
fixed
bookworm (security)
5.0.3+dfsg-3~deb12u6
fixed
forky
5.0.10+dfsg-3
fixed
sid
5.0.10+dfsg-3
fixed
trixie
5.0.7+dfsg-4+deb13u3
fixed
trixie (security)
5.0.7+dfsg-4+deb13u3
fixed