Junglewise Threat Intelligence

CVE-2026-6841: Best Practical Request Tracker reflected XSS in Page parameter

CVE-2026-6841 · Severity: info · CVSS 5.1 · Published 2026-05-21

Technologies: Best Practical Request Tracker. Vendors: Best Practical Solutions.

Executive brief

Best Practical Request Tracker, a popular open-source ticketing and workflow management system, is vulnerable to a security flaw that could allow an attacker to execute malicious scripts in a user's browser. By tricking a logged-in user into clicking a specially crafted link, an attacker could potentially steal session information or perform actions on the user's behalf. This could lead to unauthorized access to sensitive support tickets or administrative functions.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Best Practical Request Tracker (RT) versions 5.0.4 through 5.0.9 and 6.0.0 through 6.0.2. The vulnerability is located in the 'Page' URL parameter used during search operations. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing a JavaScript payload and inducing a victim (such as an agent or administrator) to visit the link. Upon interaction, the payload executes within the context of the victim's active session, potentially allowing for session hijacking or unauthorized state-changing actions. The issue is resolved in versions 5.0.10 and 6.0.3.

Affected products

  • Best Practical Request Tracker 5.0.4 to 5.0.9, 6.0.0 to 6.0.2

Timeline

  • 2026-05-20: patched: Fixed in versions 5.0.10 and 6.0.3
  • 2026-05-21: disclosed: Vulnerability disclosed by CERT Polska
  • 2026-05-21: advisory: NVD publication date

References

Related threats