Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-44231: RT Issue Tracker: Privileged User Can Steal Admin Credentials

CVE-2026-44231
Summary

RT's issue and ticket tracking system has a security flaw that allows a non-admin user to steal admin passwords and use them to access sensitive data. This happens when a user requests a specific type of data, which also exposes the admin passwords. The passwords are then changed, making previously shared links to the data useless. To fix this, update to RT version 5.0.10 or 6.0.3.

Original title
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnera...
Original description
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.
nvd CVSS3.1 9.1
Vulnerability type
CWE-200 Information Exposure
CWE-269 Improper Privilege Management
CWE-863 Incorrect Authorization
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026