CVE-2026-1836CWE-257
Stored credentials in Redmine
Medium · published June 12, 2026
What it is
The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.
The record
Technical detail
- CVSS v4.0
- 5.3 · MEDIUM
- Vector
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS
- 0.00105 · 1.1th percentile
- Weakness
- CWE-257 · Storing Passwords in a Recoverable Format
- Published
- 2026-06-12T13:23Z
EPSS history
Timeline