RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | debian-upgrade-request-tracker4debian-upgrade-request-tracker5 | Jun 7, 2026 | Jun 7, 2026 |
| Ubuntu | ubuntu-pro-upgrade-request-tracker5ubuntu-pro-upgrade-rt5-apache2ubuntu-pro-upgrade-rt5-clientsubuntu-pro-upgrade-rt5-db-mysqlubuntu-pro-upgrade-rt5-db-postgresqlubuntu-pro-upgrade-rt5-db-sqliteubuntu-pro-upgrade-rt5-fcgiubuntu-pro-upgrade-rt5-standalone | Jul 6, 2026 | May 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub