Best Practical RT fixed CVE-2026-44231, a high-severity flaw in the REST 2.0 API that let a privileged non-administrative user obtain authentication credentials belonging to other users, including administrators. The issue affected RT versions before 5.0.10 and 6.0.0 through before 6.0.3, enabling attackers to use exposed credentials to read data through RT feed endpoints while also rotating those credentials and invalidating previously distributed feed URLs across the instance.
Best Practical addressed the vulnerability in RT 5.0.10 and RT 6.0.3, and said the 6.0.3 release also fixes several other security issues, including SQL injection in JSON search, LDAP authentication bypass, CSRF, stored and reflected XSS, and spreadsheet injection in exported search results. The vendor urged users to upgrade, but also warned that a mitigation for TSV export header spreadsheet injection tied to CVE-2026-41073 was accidentally left out of RT 6.0.3, recommending a separate patch until RT 6.0.4 ships.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry documented CVE-2026-44231 as an information disclosure and privilege escalation vulnerability in Best Practical RT's REST 2.0 API. The entry states the flaw affects versions prior to 5.0.10 and 6.0.0 through before 6.0.3, and that it was fixed in versions 5.0.10 and 6.0.3.
On 2026-05-20, Best Practical released Request Tracker 6.0.3 and urged users to upgrade. The release fixed multiple vulnerabilities, including the REST 2.0 user collection endpoint flaw later tracked as CVE-2026-44231.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.