Executive brief
Request Tracker (RT), a widely used enterprise ticket and issue tracking system, contains a security flaw in how it handles user logins via LDAP or Active Directory. If the underlying directory server is configured to allow 'unauthenticated binds,' an attacker could log into the system as any legitimate user without knowing their password. This could lead to unauthorized access to sensitive internal tickets, customer data, and administrative controls.
Technical details
An authentication bypass vulnerability (CWE-287) exists in Request Tracker (RT) versions prior to 5.0.10 and 6.0.x prior to 6.0.3. The flaw occurs when RT is configured to use LDAP or Active Directory for external authentication. If the LDAP server is configured to permit unauthenticated bind attempts (often via empty passwords), RT may incorrectly validate the session, allowing a remote attacker to impersonate any LDAP-backed user. The attack complexity is rated High as it depends on specific LDAP server configurations. Patches are available in versions 5.0.10 and 6.0.3; a temporary workaround involves configuring the LDAP server to reject unauthenticated bind attempts.
Affected products
- Best Practical RT (Request Tracker) < 5.0.10, >= 6.0.0, < 6.0.3
Timeline
- 2026-05-20: patched: RT versions 5.0.10 and 6.0.3 released
- 2026-05-20: advisory: GitHub Security Advisory GHSA-3w28-fmcr-mjjx published
- 2026-05-22: disclosed: NVD publication date