CVE-2026-6841: exploitation status and patch state
CVE-2026-6841
Request Tracker is vulnerable to a reflected cross-site scripting (XSS) vulnerability via the "Page" parameter in GET requests. An attacker can craft a URL that, when opened, results in arbitrary JavaScript execution in the victim’s browser.
This vulnerability affects versions from 5.0.4 up to 5.0.9 and from 6.0.0 up to 6.0.2.
Is CVE-2026-6841 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.