SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-44228

MEDIUM · CVSS 5.4 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Versions 6.0.0 to 6.0.2 of the RT issue and ticket tracking system are vulnerable to a stored Cross-Site Scripting (XSS) flaw, allowing authenticated users to inject malicious JavaScript that executes in the context of other users. This could lead to unauthorized actions or data exposure when affected pages are viewed. Organizations using these versions should prioritize upgrading to 6.0.3 to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44228
Severity
MEDIUM
CVSS
5.4
EPSS
0.15%
Java

Original NVD Description

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 and above, prior to 6.0.3, contain a stored Cross-Site Scripting (XSS) vulnerability, where user-controlled data is rendered without proper HTML escaping. An authenticated user with permission to set the relevant data can inject JavaScript that executes when another RT user views the affected page. This issue has been fixed in version 6.0.3.

Related CVEs

Other vulnerabilities affecting the same vendor(s)