RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing actions in RT on that user's behalf. This issue has been fixed in version 6.0.3.
References
Configurations
No configuration.
History
23 Jul 2026, 11:10
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
22 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-22 22:16
Updated : 2026-07-23 11:10
NVD link : CVE-2026-41074
Mitre link : CVE-2026-41074
CVE.ORG link : CVE-2026-41074
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
