CVE-2026-1836
Redmine vulnerability analysis and mitigation

Overview

CVE-2026-1836 is a credential storage vulnerability in Redmine, the open-source project management platform, where the system stores usernames and passwords from the login form after form submission, allowing an attacker with local or physical access to the browser to retrieve those credentials. It affects Redmine versions prior to 5.0.14, prior to 5.1.10, and prior to 6.0.7. The vulnerability was published on June 12, 2026, and assigned by INCIBE. It carries a CVSS v4.0 base score of 5.3 (Medium) (GitHub Advisory, INCIBE).

Technical details

The root cause is classified as CWE-257 (Storing Passwords in a Recoverable Format): Redmine's login form does not prevent the browser from caching or autosaving submitted credentials, resulting in plaintext or recoverable credentials being stored in browser storage mechanisms (e.g., browser password manager, form autofill cache). Exploitation requires local or physical access to the affected machine, low-level privileges on the platform, and active user interaction (a prior login session). No public proof-of-concept exploit code has been identified (GitHub Advisory, INCIBE).

Impact

Successful exploitation allows an attacker with local or physical access to the browser session to retrieve valid Redmine login credentials (username and password), resulting in high confidentiality and integrity impact to the vulnerable system. Recovered credentials could be reused to authenticate to the Redmine instance or other services where the victim reuses passwords, enabling unauthorized access to project data, issue tracking, and potentially sensitive organizational information. Availability is not impacted by this vulnerability (GitHub Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a public proof-of-concept for CVE-2026-1836 at this time. The EPSS score is approximately 0.013% (1st percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained to local or physical attackers who have access to the victim's browser session, significantly limiting the attack surface (GitHub Advisory, INCIBE).

Exploitation steps

  1. Gain local access: Obtain physical or local access to a machine where a user has previously logged into a vulnerable Redmine instance (versions < 5.0.14, < 5.1.10, or < 6.0.7).
  2. Open the browser: Launch the browser used by the victim to access Redmine (e.g., Chrome, Firefox, Edge).
  3. Navigate to Redmine login page: Browse to the Redmine login URL used by the victim.
  4. Access stored credentials: Use the browser's built-in password manager or autofill feature (e.g., browser settings → Passwords, or inspect autofill suggestions on the login form) to view the cached username and password submitted during the prior session.
  5. Authenticate as victim: Use the retrieved credentials to log into Redmine or attempt credential reuse on other services (GitHub Advisory, INCIBE).

Indicators of compromise

  • Logs: Unexpected or anomalous Redmine login events from the same machine at unusual times or outside normal working hours, potentially indicating credential reuse after local access.
  • Browser Artifacts: Presence of saved Redmine credentials in the browser's password manager (e.g., Chrome's Login Data SQLite file, Firefox's logins.json) on shared or multi-user systems.
  • Access Logs: Redmine application logs showing successful authentication from a user account at a time inconsistent with that user's normal activity pattern.

Mitigation and workarounds

Update Redmine to the patched versions: 5.0.14, 5.1.10, or 6.0.7 or later, which address this credential storage issue. As a configuration-based workaround, administrators should add autocomplete="off" to the login form (if not already applied by the patch) and configure browser policies to disable credential caching for the Redmine domain. Users — especially on shared systems — should be advised to clear browser-saved passwords and cache after login sessions, and organizations should enforce multi-factor authentication where possible to reduce the impact of credential exposure (INCIBE, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Redmine vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-47260MEDIUM6.1
  • Redmine logoRedmine
  • redmine
NoYesNov 05, 2023
CVE-2023-47259MEDIUM6.1
  • Redmine logoRedmine
  • redmine
NoYesNov 05, 2023
CVE-2023-47258MEDIUM6.1
  • Redmine logoRedmine
  • redmine
NoYesNov 05, 2023
CVE-2026-1836MEDIUM5.3
  • Redmine logoRedmine
  • redmine
NoYesJun 12, 2026
CVE-2025-4011MEDIUM5.1
  • Redmine logoRedmine
  • redmine
NoYesApr 28, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management