VORANT. Threat Intelligence Sign in Get the full feed

CERT Polska discloses Request Tracker XSS flaw

low vulnerability

A reflected XSS vulnerability in Best Practical Request Tracker (CVE-2026-6841) lets attackers run JavaScript in a victim's browser via a crafted URL.

CERT Polska researcher Aleksander Iwicki discovered a reflected cross-site scripting vulnerability in Best Practical's Request Tracker, a widely used ticketing/helpdesk system, and coordinated its disclosure as CVE-2026-6841. The flaw resides in handling of the Page parameter in GET requests, allowing an attacker to craft a malicious URL that, when clicked by a victim, executes arbitrary JavaScript in the browser context of the logged-in user.

The vulnerability affects Request Tracker versions 5.0.4 through 5.0.9 and 6.0.0 through 6.0.2. As with typical reflected XSS issues, exploitation requires social engineering to get a target to click a crafted link, and impact is scoped to the victim's browser session (e.g., session hijacking, credential theft, or unauthorized actions within RT). No evidence of in-the-wild exploitation is mentioned in the disclosure; this appears to be a proactively identified and responsibly disclosed issue handled through CERT Polska's coordinated vulnerability disclosure process.

Organizations running affected Request Tracker versions should apply vendor patches once available and monitor Best Practical's advisories for remediation guidance.

Mentioned in this report

Vulnerabilities CVE-2026-6841

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-6841

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free