CVE-2026-41074: Bestpractical Rt
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing actions in RT on that user's behalf. This issue has been fixed in version 6.0.3.
Affected products
- Bestpractical Rt: from 6.0.0, before 6.0.3 (fixed in 6.0.3)
Published 2026-05-22. Last modified 2026-07-23.