Junglewise Threat Intelligence

CVE-2026-44230: Best Practical RT reflected XSS in search results chart

CVE-2026-44230 · Severity: medium · CVSS 6.1 · Published 2026-07-20

Technologies: Best Practical RT. Vendors: Best Practical Solutions.

Executive brief

Best Practical RT (Request Tracker), an enterprise-grade ticket tracking system, is vulnerable to a security flaw in its search results chart pages. An attacker can trick a logged-in user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of session information or the performance of unauthorized actions on behalf of the user.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in Best Practical RT within the search-results chart component. The vulnerability is caused by improper neutralization of user-controllable input before it is rendered on the page (CWE-79). An unauthenticated remote attacker can exploit this by crafting a malicious URL and tricking an authenticated user into visiting it (User Interaction required). Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized state-changing actions. The issue is fixed in versions 5.0.10 and 6.0.3.

Affected products

  • Best Practical RT >= 5.0.4, < 5.0.10; >= 6.0.0, < 6.0.3

Timeline

  • 2026-05-20: patched: Fixes released in versions 5.0.10 and 6.0.3
  • 2026-05-20: advisory: GitHub Security Advisory GHSA-p724-v26h-32g9 published
  • 2026-07-20: disclosed: CVE-2026-44230 published to NVD

References

Related threats