Unrated severityNVD Advisory· Published May 22, 2026
RT has broken CSRF protection for authenticated users
CVE-2026-41074
Description
RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing actions in RT on that user's behalf. This issue has been fixed in version 6.0.3.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/bestpractical/rt/releases/tag/rt-6.0.3mitrex_refsource_MISC
- github.com/bestpractical/rt/security/advisories/GHSA-265j-qx4w-256jmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.