{"id":"CVE-2026-41074","title":"RT is an open source, enterprise-grade issue and ticket tracking system","summary":"RT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page…","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L","cwe":["CWE-352"],"published":"2026-05-22","updated":"2026-07-23","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-41074","references":[{"url":"https://github.com/bestpractical/rt/releases/tag/rt-6.0.3","label":"security-advisories@github.com"},{"url":"https://github.com/bestpractical/rt/security/advisories/GHSA-265j-qx4w-256j","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00173,"epssPercentile":0.05991,"ingestedAt":"2026-07-23T11:17:34.272Z","slug":"CVE-2026-41074","body":"## Overview\n\nRT is an open source, enterprise-grade issue and ticket tracking system. Versions 6.0.0 through 6.0.2 contain a Cross-Site Request Forgery (CSRF) vulnerability. An attacker who can induce a logged-in RT user to visit a malicious web page can trigger arbitrary state-changing actions in RT on that user's behalf. This issue has been fixed in version 6.0.3.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}