CERT Polska discloses Request Tracker XSS flaw
A reflected XSS vulnerability in Best Practical Request Tracker (CVE-2026-6841) lets attackers run JavaScript in a victim's browser via a crafted URL.
CERT Polska researcher Aleksander Iwicki discovered a reflected cross-site scripting vulnerability in Best Practical's Request Tracker, a widely used ticketing/helpdesk system, and coordinated its disclosure as CVE-2026-6841. The flaw resides in handling of the Page parameter in GET requests, allowing an attacker to craft a malicious URL that, when clicked by a victim, executes arbitrary JavaScript in the browser context of the logged-in user.
The vulnerability affects Request Tracker versions 5.0.4 through 5.0.9 and 6.0.0 through 6.0.2. As with typical reflected XSS issues, exploitation requires social engineering to get a target to click a crafted link, and impact is scoped to the victim's browser session (e.g., session hijacking, credential theft, or unauthorized actions within RT). No evidence of in-the-wild exploitation is mentioned in the disclosure; this appears to be a proactively identified and responsibly disclosed issue handled through CERT Polska's coordinated vulnerability disclosure process.
Organizations running affected Request Tracker versions should apply vendor patches once available and monitor Best Practical's advisories for remediation guidance.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-6841
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free