« Volver al listado

CVE-2026-41075

Estado: AplazadaAlta (8.8)—

RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries without proper validation, potentially allowing them to read or modify data in the RT database. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by restricting RT account access to trusted users.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

SQL injection (CWE-89) en RT con acceso de red y autenticación requerida (AV:N, PR:L). Impactos: lectura de datos (C:H), modificación de BD (I:H), escalada vía privilegios de BD (A:H).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-41075",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-41075",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-27T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "bestpractical",
          "product": "rt",
          "versions": [
            {
              "status": "affected",
              "version": ">= 5.0.0, < 5.0.10"
            },
            {
              "status": "affected",
              "version": ">= 6.0.0, < 6.0.3"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-22T22:16:55.940",
  "references": [
    {
      "url": "https://github.com/bestpractical/rt/releases/tag/rt-5.0.10",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/bestpractical/rt/releases/tag/rt-6.0.3",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/bestpractical/rt/security/advisories/GHSA-7vf8-xv7w-97c6",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "RT is an open source, enterprise-grade issue and ticket tracking system. Versions 5.0.0 through 5.0.9 and 6.0.0 through 6.0.2 contain an SQL injection vulnerability. An authenticated user can craft input that is incorporated into database queries without proper validation, potentially allowing them to read or modify data in the RT database. This issue has been fixed in versions 5.0.10 and 6.0.3. If developers are unable to upgrade immediately, they can temporarily work around this issue by restricting RT account access to trusted users."
    },
    {
      "lang": "es",
      "value": "RT es un sistema de seguimiento de problemas y tickets de código abierto, de nivel empresarial. Las versiones 5.0.0 a 5.0.9 y 6.0.0 a 6.0.2 contienen una vulnerabilidad de inyección SQL. Un usuario autenticado puede crear una entrada que se incorpora en consultas de base de datos sin la validación adecuada, lo que potencialmente les permite leer o modificar datos en la base de datos de RT. Este problema ha sido solucionado en las versiones 5.0.10 y 6.0.3. Si los desarrolladores no pueden actualizar inmediatamente, pueden solucionar temporalmente este problema restringiendo el acceso a la cuenta de RT a usuarios de confianza."
    }
  ],
  "lastModified": "2026-07-23T11:10:00.120",
  "sourceIdentifier": "security-advisories@github.com"
}