CVE-2026-44231
RT is an open‑source issue tracking system. A flaw in its REST 2.0 API lets a non‑admin user steal the credentials of other users, including administrators, and read data as them. The vulnerability was fixed in RT 5.0.10 and 6.0.3.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
RT (Redmine Ticketing) versions prior to 5.0.10 and 6.0.0‑6.0.2. Users running those releases are affected.
Real-world impact
An attacker could obtain other users’ login tokens and impersonate them to view confidential data, and could also invalidate existing feed URLs, disrupting legitimate data feeds.
Why this severity
The CVSS score of 9.1 reflects that the flaw can be exploited over the network with low effort, requires only a privileged user, and allows an attacker to gain high confidentiality impact by stealing credentials. The scope change and high confidentiality rating drive the critical score.
What to do about it
- 01Upgrade RT to version 5.0.10 or later (for 5.x releases) or to version 6.0.3 or later (for 6.x releases).
NVD-referenced vendor advisory
Timeline
- Jul 20, 2026 · 13d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 20, 2026 · 12d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
- Jul 23, 2026 · 10d agoAdvisory updatedThe NVD record was last revised.