CVE-2026-44230
Description
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.4 up to (but not including) 5.0.10, and 6.0.0 up to (but not including) 6.0.3 contain a reflected Cross-Site Scripting (XSS) vulnerability where an attacker who can induce an authenticated RT user to visit a crafted URL can execute arbitrary JavaScript in that user's browser session. This issue has been fixed in versions 5.0.10 and 6.0.3.
How to fix CVE-2026-44230
To remediate CVE-2026-44230, upgrade the affected package to a fixed version below.
- Debian/request-tracker5—upgrade to 5.0.7+dfsg-4+deb13u3 or later
Is CVE-2026-44230 being exploited?
No exploitation signal available. Neither CISA KEV nor a current EPSS score has been published for CVE-2026-44230.
Affected packages (1)
- from 0, < 5.0.7+dfsg-4+deb13u3