Junglewise Threat Intelligence

CVE-2026-44231: Best Practical RT privilege escalation in REST 2.0 API

CVE-2026-44231 · Severity: critical · CVSS 9.1 · Published 2026-07-20

Technologies: Best Practical Solutions Request Tracker. Vendors: Best Practical Solutions.

Executive brief

Request Tracker (RT), a widely used enterprise ticket and issue tracking system, contains a security flaw in its programming interface. This vulnerability allows a standard user to steal the login credentials of other users, including system administrators. An attacker could use these stolen credentials to access sensitive internal data and private ticket information, potentially leading to a significant breach of corporate confidentiality.

Technical details

An information disclosure and privilege escalation vulnerability exists in the REST 2.0 user collection endpoint of Best Practical RT. The flaw allows a privileged (but non-administrative) user to retrieve authentication credentials belonging to other users, including administrators, via the REST 2.0 API. These credentials can then be used to access data through RT's RSS and iCal feed endpoints. Exploitation also triggers a rotation of the exposed credentials, which may cause service disruption by invalidating existing legitimate feed URLs. The issue is fixed in versions 5.0.10 and 6.0.3.

Affected products

  • Best Practical RT (Request Tracker) < 5.0.10, >= 6.0.0, < 6.0.3

Timeline

  • 2026-05-20: patched: Versions 5.0.10 and 6.0.3 released
  • 2026-05-20: advisory: GitHub Security Advisory published
  • 2026-07-20: disclosed: NVD publication date

References

Related threats