| CVE ID | CVE-2026-6841 |
| Publication date | 21 May 2026 |
| Vendor | Best Practical |
| Product | Request Tracker |
| Vulnerable versions | From 5.0.4 below 5.0.10 From 6.0.0 below 6.0.3 |
| Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
| Report source | Own research |
Description
CERT Polska during own research has found a vulnerability in Best Practical Request Tracker software and participated in coordination of its disclosure.
The vulnerability CVE-2026-6841: Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the Page parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser.
This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to 6.0.2.
Credits
The vulnerability was found by Aleksander Iwicki from CERT Polska.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.