CVE-2026-1836

EUVD-2026-36424
The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
INCIBECNA
5.3 MEDIUM
LOCAL
LOW
LOW
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.16%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
redmineredmine
𝑥
< 6.0.7
CNA
redmineredmine
𝑥
< 5.1.10
CNA
redmineredmine
𝑥
< 5.0.14
CNA
Debian logo
Debian Releases
Debian Product
Codename
redmine
bookworm
postponed
bookworm (security)
vulnerable
forky
6.1.3+ds-3
fixed
sid
6.1.3+ds-3
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
redmine
bionic
needs-triage
focal
needs-triage
jammy
dne
noble
dne
questing
dne
resolute
dne
xenial
needs-triage