# CVE-2026-1836

## Summary

- **CVE ID:** CVE-2026-1836
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-257
- **Published:** Jun 12, 2026
- **Last Modified:** Jun 12, 2026

## Description

The system stores the username and password from the login form after submitting the request. This could allow an attacker with access to the platform to return to the browser and view the login credentials.

## Affected Products

- Redmine — Redmine (0)
- Redmine — Redmine (6.0.7)
- Redmine — Redmine (5.1.10)
- Redmine — Redmine (5.0.14)

## References

- [CNA](https://www.incibe.es/en/incibe-cert/notices/aviso/stored-credentials-redmine)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.10%
- **EPSS Percentile:** 1.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._