
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1836 is a credential storage vulnerability in Redmine, the open-source project management platform, where the system stores usernames and passwords from the login form after form submission, allowing an attacker with local or physical access to the browser to retrieve those credentials. It affects Redmine versions prior to 5.0.14, prior to 5.1.10, and prior to 6.0.7. The vulnerability was published on June 12, 2026, and assigned by INCIBE. It carries a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, INCIBE).
The root cause is classified as CWE-257 (Storing Passwords in a Recoverable Format): Redmine's login form does not prevent the browser from caching or autosaving submitted credentials, resulting in plaintext or recoverable credentials being stored in browser storage mechanisms (e.g., browser password manager, form autofill cache). Exploitation requires local or physical access to the affected machine, low-level privileges on the platform, and active user interaction (a prior login session). No public proof-of-concept exploit code has been identified (GitHub Advisory, INCIBE).
Successful exploitation allows an attacker with local or physical access to the browser session to retrieve valid Redmine login credentials (username and password), resulting in high confidentiality and integrity impact to the vulnerable system. Recovered credentials could be reused to authenticate to the Redmine instance or other services where the victim reuses passwords, enabling unauthorized access to project data, issue tracking, and potentially sensitive organizational information. Availability is not impacted by this vulnerability (GitHub Advisory).
There is no evidence of active in-the-wild exploitation or a public proof-of-concept for CVE-2026-1836 at this time. The EPSS score is approximately 0.013% (1st percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained to local or physical attackers who have access to the victim's browser session, significantly limiting the attack surface (GitHub Advisory, INCIBE).
Login Data SQLite file, Firefox's logins.json) on shared or multi-user systems.Update Redmine to the patched versions: 5.0.14, 5.1.10, or 6.0.7 or later, which address this credential storage issue. As a configuration-based workaround, administrators should add autocomplete="off" to the login form (if not already applied by the patch) and configure browser policies to disable credential caching for the Redmine domain. Users — especially on shared systems — should be advised to clear browser-saved passwords and cache after login sessions, and organizations should enforce multi-factor authentication where possible to reduce the impact of credential exposure (INCIBE, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."