PT-2026-48867 · Redmine+2 · Redmine

CVE-2026-1836

·

Published

2026-06-12

·

Updated

2026-06-12

CVSS v4.0

5.3

Medium

VectorAV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description The system stores the username and password from the login form after the request is submitted. This behavior may allow an attacker with access to the platform to retrieve the login credentials by returning to the browser.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1836

Affected Products

Redmine