CVE 5.3 MEDIUM

Stored credentials in Redmine_CVE-2026-1836

5.3 / 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

Basic Information

ID CVE-2026-1836
Source INCIBE
Published Jun 12, 2026 at 13:23

Affected Product

Vendor Redmine
Product Redmine
Affected Versions Redmine Redmine 0
Redmine Redmine 0
Redmine Redmine 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.