CVE-2026-1836 PUBLISHED

Stored credentials in Redmine

Assigner: INCIBE
Reserved: 03.02.2026 Published: 12.06.2026 Updated: 12.06.2026

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor Redmine
Product Redmine
Versions Default: unaffected
  • affected from 0 to 6.0.7 (excl.)
  • affected from 0 to 5.1.10 (excl.)
  • affected from 0 to 5.0.14 (excl.)
  • Version 6.0.7 is unaffected
  • Version 5.1.10 is unaffected
  • Version 5.0.14 is unaffected

Solutions

The vulnerability has been fixed by Redmine team in versions 6.0.7, 5.1.10 and 5.0.14.

References

Problem Types

  • CWE-257 Storing passwords in a recoverable format CWE