Executive brief
Best Practical RT, an enterprise-grade ticket and issue tracking system, is vulnerable to a security flaw that could allow an authorized user to access or modify sensitive database information. By submitting specially crafted search requests, a user with a standard account could bypass security controls to view or change data they should not have access to. This could lead to the exposure of confidential support tickets, customer data, or the unauthorized modification of system records.
Technical details
An SQL injection vulnerability exists in Best Practical RT versions 5.0.x (before 5.0.10) and 6.0.x (before 6.0.3). The flaw is located in the 'entry_aggregator' parameter within the JSON search functionality. An authenticated attacker can provide unvalidated input that is directly incorporated into database queries. This allows for the execution of arbitrary SQL commands, potentially leading to full database compromise, including the ability to read, modify, or delete data. The vulnerability is reachable over the network but requires at least low-level user authentication. Patches are available in versions 5.0.10 and 6.0.3.
Affected products
- Best Practical RT (Request Tracker) 5.0.0 to 5.0.9, 6.0.0 to 6.0.2
Timeline
- 2026-05-20: patched: Versions 5.0.10 and 6.0.3 released
- 2026-05-20: advisory: GitHub Security Advisory published
- 2026-05-22: disclosed: CVE published to NVD