# CERT Polska disclosed CVE-2026-6841, a reflected XSS vulnerability in Best Practical…

Published: 2026-05-21 · Severity: medium
Canonical: https://vorant.io/reports/fea330a1-10f5-4c2d-86b6-eba5b21dfdf8/cert-polska-disclosed-cve-2026-6841-a-reflected-xss-vulnerability-in-best

> CERT Polska disclosed CVE-2026-6841, a reflected XSS vulnerability in Best Practical Request Tracker versions 5.0.4-5.0.9 and 6.0.0-6.0.2 via the Page parameter.

CERT Polska researcher Aleksander Iwicki discovered a reflected cross-site scripting (XSS) vulnerability in Best Practical Request Tracker, a widely-used ticketing and incident response system. The vulnerability, tracked as CVE-2026-6841, allows an attacker to craft malicious URLs containing JavaScript payloads in the Page parameter of GET requests. When a victim opens such a URL, arbitrary JavaScript executes in their browser context, potentially enabling session hijacking, credential theft, or other client-side attacks.

The vulnerability affects Request Tracker versions 5.0.4 through 5.0.9 and 6.0.0 through 6.0.2. CERT Polska participated in coordinated disclosure of this issue with the vendor. Organizations running affected versions should prioritize patching, as XSS vulnerabilities in ticketing systems can be leveraged in social engineering campaigns targeting IT and security teams who routinely handle external links.

No evidence of active exploitation has been reported at this time. The discovery underscores the value of independent security research and coordinated vulnerability disclosure programs in identifying and remediating security issues before they can be weaponized.

## Mentioned in this report

- Vulnerabilities: CVE-2026-6841

## Detection guidance (public sample)

### Possible Reflected XSS Attempt Against Request Tracker Page Parameter (CVE-2026-6841)

ATT&CK: T1189

Detects HTTP GET requests to Request Tracker containing script-like payloads in the Page parameter, consistent with reflected XSS exploitation delivered via spearphishing links. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Possible Reflected XSS Attempt Against Request Tracker Page Parameter
id: 7f71e166-cebb-57a2-a742-0eae6c7a23dd
status: experimental
description: 'Detects HTTP GET requests targeting Best Practical Request Tracker where
  the

  ''Page'' query parameter contains script tags, javascript: URIs, or event

  handler payloads consistent with exploitation of CVE-2026-6841, a reflected

  XSS vulnerability. Attackers typically deliver such crafted URLs via

  spearphishing links or drive-by pages to IT/security staff who handle

  ticketing links routinely.

  '
references:
- https://cert.pl
author: Vorant
logsource:
  category: webserver
detection:
  selection_param:
    cs-uri-query|contains: Page=
  selection_payload:
    cs-uri-query|contains:
    - <script
    - 'javascript:'
    - onerror=
    - onload=
    - '%3Cscript'
    - onmouseover=
  condition: selection_param and selection_payload
falsepositives:
- Automated web application vulnerability scanners (e.g., Burp Suite, ZAP) testing
  the RT instance
- Legitimate use of Page parameter containing encoded special characters that superficially
  match patterns
level: medium
tags:
- attack.t1189
- attack.t1566.002
- cve.2026.6841
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-6841

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/fea330a1-10f5-4c2d-86b6-eba5b21dfdf8/cert-polska-disclosed-cve-2026-6841-a-reflected-xss-vulnerability-in-best.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
