Junglewise Threat Intelligence

CVE-2026-1836: Redmine insecure credential storage in login form

CVE-2026-1836 · Severity: info · CVSS 5.3 · Published 2026-06-12

Executive brief

Redmine is a popular web-based project management and issue tracking tool. A security issue in its login process causes the application to store user credentials in the browser's memory or history after a login attempt. This could allow a person with physical or local access to a shared computer to recover the previous user's username and password, potentially leading to unauthorized account access.

Technical details

A vulnerability classified as CWE-257 (Storing Passwords in a Recoverable Format) exists in the Redmine login form. The application fails to properly clear or protect sensitive form data after submission, causing the browser to retain the username and password in its state or history. An attacker with local access to the victim's browser session can navigate back or inspect the browser state to retrieve plaintext credentials. This issue affects all Redmine versions prior to 6.0.7, 5.1.10, and 5.0.14. Users are advised to upgrade to the patched versions to ensure credentials are not cached or stored insecurely by the client-side interface.

Affected products

  • Redmine Redmine Prior to 6.0.7, 5.1.10, and 5.0.14

Timeline

  • 2026-03-31: advisory: Initial INCIBE-CERT advisory published
  • 2026-06-12: disclosed: CVE published to NVD dataset

References