Junglewise Threat Intelligence

CVE-2026-41074: Best Practical RT Cross-Site Request Forgery

CVE-2026-41074 · Severity: high · CVSS 7.1 · Published 2026-05-22

Technologies: Best Practical Solutions Request Tracker. Vendors: Best Practical Solutions.

Executive brief

Best Practical RT, an enterprise-grade ticket tracking system, contains a vulnerability that could allow an attacker to perform actions as a legitimate user. By tricking a logged-in staff member or administrator into visiting a malicious website, an attacker can silently trigger changes within the tracking system, such as modifying tickets or changing settings. This could lead to unauthorized data modification or disruption of support operations.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in RT 6.0.0 through 6.0.2 due to insufficient verification of whether requests were intentionally initiated by the authenticated user. An attacker can exploit this by hosting a malicious web page and inducing a logged-in RT user to visit it (User Interaction required). Successful exploitation allows the attacker to execute arbitrary state-changing actions, such as modifying ticket data or system configurations, with the privileges of the victim user. The vulnerability is addressed in version 6.0.3.

Affected products

  • Best Practical RT (Request Tracker) 6.0.0 through 6.0.2

Timeline

  • 2026-05-20: patched: RT version 6.0.3 released
  • 2026-05-20: advisory: GitHub Security Advisory GHSA-265j-qx4w-256j published
  • 2026-05-22: disclosed: CVE-2026-41074 published to NVD

References

Related threats