๐Ÿ” CVE Alert

CVE-2026-1836

UNKNOWN 0.0

Stored credentials in Redmine

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

CWE CWE-257
Vendor redmine
Product redmine
Published Jun 12, 2026
Last Updated Jun 12, 2026
Stay Ahead of the Next One

Get instant alerts for redmine redmine

Be the first to know when new unknown vulnerabilities affecting redmine redmine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Redmine / Redmine
0 < 6.0.7 0 < 5.1.10 0 < 5.0.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/stored-credentials-redmine