PT-2026-45155 · Rt+2 · Rt+2

CVE-2026-44231

·

Published

2026-05-20

·

Updated

2026-08-07

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions RT versions prior to 5.0.10 RT versions 6.0.0 through 6.0.2
Description An information disclosure and privilege escalation issue exists in the REST 2.0 API. A privileged user without administrative rights can obtain authentication credentials of other users, including administrators. These credentials allow the attacker to read data through feed endpoints. The request used to expose these credentials also triggers a rotation, which invalidates all previously distributed feed URLs across the instance.
Recommendations Update to version 5.0.10. Update to version 6.0.3.

Exploit

Fix

DoS

LPE

Information Disclosure

Improper Privilege Management

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44231
GHSA-7RX2-X357-WV74
USN-8506-1

Affected Products

Linuxmint
Rt
Ubuntu