XSS via Inline Upload in RT 5.0.0-5.0.9 & 6.0.0-6.0.2
CVE-2026-44229 Published on July 20, 2026

RT: Cross-Site Scripting via inline-served uploaded content
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 and 6.0.0 and above, prior to both 5.0.10 and 6.0.3 contain a Cross-Site Scripting (XSS) vulnerability where uploaded content is served inline rather than as an attachment. An authenticated user who can upload content can include JavaScript in the upload that will execute in the browser session of any RT user who later views or downloads it. This issue has been fixed in versions 5.0.10 and 6.0.3.

NVD

Vulnerability Analysis

CVE-2026-44229 can be exploited with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality and integrity, and no impact on availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
LOW
User Interaction:
REQUIRED
Scope:
CHANGED
Confidentiality Impact:
LOW
Integrity Impact:
LOW
Availability Impact:
NONE

Weakness Type

What is a XSS Vulnerability?

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

CVE-2026-44229 has been classified to as a XSS vulnerability or weakness.


Products Associated with CVE-2026-44229

stack.watch emails you whenever new vulnerabilities are published in Canonical Ubuntu Linux or Bestpractical Rt. Just hit a watch button to start following.

 
 

Affected Versions

bestpractical rt: