Vulnary
← back to the feed
Critical· 9.1official fix available

CVE-2026-44231

RT is an open‑source issue tracking system. A flaw in its REST 2.0 API lets a non‑admin user steal the credentials of other users, including administrators, and read data as them. The vulnerability was fixed in RT 5.0.10 and 6.0.3.

publishedJul 20, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.1
critical · how bad it is
exploitation · epss
<1%
16th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Aug 19, 2026

An official fix is available, so this entry is kept for 30 days and then removed automatically.

01

Who is affected

RT (Redmine Ticketing) versions prior to 5.0.10 and 6.0.0‑6.0.2. Users running those releases are affected.

02

Real-world impact

An attacker could obtain other users’ login tokens and impersonate them to view confidential data, and could also invalidate existing feed URLs, disrupting legitimate data feeds.

03

Why this severity

The CVSS score of 9.1 reflects that the flaw can be exploited over the network with low effort, requires only a privileged user, and allows an attacker to gain high confidentiality impact by stealing credentials. The scope change and high confidentiality rating drive the critical score.

04

What to do about it

official fix available
recommended steps
  1. 01Upgrade RT to version 5.0.10 or later (for 5.x releases) or to version 6.0.3 or later (for 6.x releases).

NVD-referenced vendor advisory

05

Timeline

  1. Jul 20, 2026 · 13d ago
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 20, 2026 · 12d ago
    Official fix available
    A vendor patch or mitigation now exists — see the remediation steps above.
  3. Jul 23, 2026 · 10d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredLow
User interactionNone needed
ScopeChanged
Confidentiality impactHigh
Integrity impactLow
Availability impactLow
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →