XSS via Inline Upload in RT 5.0.0-5.0.9 & 6.0.0-6.0.2
CVE-2026-44229 Published on July 20, 2026
RT: Cross-Site Scripting via inline-served uploaded content
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.
Vulnerability Analysis
CVE-2026-44229 can be exploited with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is a XSS Vulnerability?
The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2026-44229 has been classified to as a XSS vulnerability or weakness.
Products Associated with CVE-2026-44229
stack.watch emails you whenever new vulnerabilities are published in Canonical Ubuntu Linux or Bestpractical Rt. Just hit a watch button to start following.
Affected Versions
bestpractical rt:- Version >= 6.0.0, < 6.0.3 is affected.
- Version >= 5.0.0, < 5.0.10 is affected.