CVE-2026-1836

MEDIUM

Stored credentials in Redmine

Title source: cna
STIX 2.1

Description

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

References (1)

Core 1

Scores

CVSS v4 5.3
EPSS 0.0010
EPSS Percentile 1.3%
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-257
Status published
Products (6)
Redmine/Redmine < 5.0.14
Redmine/Redmine < 5.1.10
Redmine/Redmine < 6.0.7
Redmine/Redmine 5.0.14
Redmine/Redmine 5.1.10
Redmine/Redmine 6.0.7
Published Jun 12, 2026
Tracked Since Jun 12, 2026