Junglewise Threat Intelligence

CVE-2026-41073: Best Practical RT spreadsheet injection in ticket exports

CVE-2026-41073 · Severity: medium · CVSS 4.6 · Published 2026-05-22

Technologies: Best Practical Solutions RT. Vendors: Best Practical Solutions.

Executive brief

Best Practical RT, an enterprise ticket tracking system, is vulnerable to spreadsheet injection. An attacker can input malicious data into a ticket that, when exported to a CSV or Excel file by another user, could execute unauthorized commands or formulas on that user's computer. This could lead to the theft of sensitive information or unauthorized data modification on the victim's local system.

Technical details

A CSV/formula injection vulnerability (CWE-1236) exists in RT's spreadsheet export functionality. User-controlled data in ticket values is not properly sanitized before being written to export files, allowing an attacker with low privileges to inject crafted values starting with formula characters (e.g., =, +, -, @). When a victim exports these results and opens the file in a spreadsheet application like Microsoft Excel, the application may interpret these values as formulas or macros. This can lead to information disclosure or limited integrity impact on the victim's machine. The issue is fixed in versions 5.0.10 and 6.0.3, though users of 6.0.3 should also apply a manual patch for TSV export headers.

Affected products

  • Best Practical RT (Request Tracker) < 5.0.10, 6.0.0 - 6.0.2

Timeline

  • 2026-05-20: patched: Versions 5.0.10 and 6.0.3 released
  • 2026-05-22: advisory: NVD publication date

References

Related threats