The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

Project Subscriptions

Vendors Products
Redmine Subscribe
Redmine Subscribe
Advisories

No advisories yet.

Fixes

Solution

The vulnerability has been fixed by Redmine team in versions 6.0.7, 5.1.10 and 5.0.14.


Workaround

No workaround given by the vendor.

History

Fri, 12 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 12 Jun 2026 13:45:00 +0000

Type Values Removed Values Added
Description The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.
Title Stored credentials in Redmine
First Time appeared Redmine
Redmine redmine
Weaknesses CWE-257
CPEs cpe:2.3:a:redmine:redmine:*:*:*:*:*:*:*:*
cpe:2.3:a:redmine:redmine:5.0.14:*:*:*:*:*:*:*
cpe:2.3:a:redmine:redmine:5.1.10:*:*:*:*:*:*:*
cpe:2.3:a:redmine:redmine:6.0.7:*:*:*:*:*:*:*
Vendors & Products Redmine
Redmine redmine
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-06-12T14:00:11.755Z

Reserved: 2026-02-03T15:43:30.850Z

Link: CVE-2026-1836

cve-icon Vulnrichment

Updated: 2026-06-12T14:00:07.862Z

cve-icon NVD

Status : Received

Published: 2026-06-12T14:16:30.817

Modified: 2026-06-12T14:16:30.817

Link: CVE-2026-1836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses