Executive brief
Request Tracker (RT), a widely used enterprise ticket and issue tracking system, contains a security flaw in its programming interface. This vulnerability allows a standard user to steal the login credentials of other users, including system administrators. An attacker could use these stolen credentials to access sensitive internal data and private ticket information, potentially leading to a significant breach of corporate confidentiality.
Technical details
An information disclosure and privilege escalation vulnerability exists in the REST 2.0 user collection endpoint of Best Practical RT. The flaw allows a privileged (but non-administrative) user to retrieve authentication credentials belonging to other users, including administrators, via the REST 2.0 API. These credentials can then be used to access data through RT's RSS and iCal feed endpoints. Exploitation also triggers a rotation of the exposed credentials, which may cause service disruption by invalidating existing legitimate feed URLs. The issue is fixed in versions 5.0.10 and 6.0.3.
Affected products
- Best Practical RT (Request Tracker) < 5.0.10, >= 6.0.0, < 6.0.3
Timeline
- 2026-05-20: patched: Versions 5.0.10 and 6.0.3 released
- 2026-05-20: advisory: GitHub Security Advisory published
- 2026-07-20: disclosed: NVD publication date